{"grype_matches":[{"artifact":{"id":"dda23e04d31afbbd","cpes":["cpe:2.3:a:apache:solr-core:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:solr_core:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:solr:10.0.0:*:*:*:*:*:*:*"],"name":"solr-core","purl":"pkg:maven/org.apache.solr/solr-core@10.0.0","type":"java-archive","version":"10.0.0","language":"java","licenses":["Apache-2.0","MIT"],"metadata":{"pomGroupID":"org.apache.solr","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/solr-core-10.0.0.jar","manifestName":"","pomArtifactID":"solr-core","archiveDigests":[{"value":"18e0831c459a1624eaa17f2ccf7c055ce8049f41","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/solr-core-10.0.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/solr-core-10.0.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-h655-pw6r","versionConstraint":"=10.0.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.solr:solr-core","version":"10.0.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qhr7-h655-pw6r","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44825","cwe":"CWE-798","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-44825","cwe":"CWE-1188","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-44825","date":"2026-10-08","epss":0.02838,"percentile":0.86237}],"risk":2.21364,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-44825","https://lists.apache.org/thread/5xg6xr99glocp3zsg9ht2zlbwlrst7ch","http://www.openwall.com/lists/oss-security/2026/05/29/6"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-h655-pw6r","description":"Apache Solr has hardcoded credentials in the Basic Authentication setup tool"},"relatedVulnerabilities":[{"id":"CVE-2026-44825","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44825","cwe":"CWE-798","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-44825","cwe":"CWE-1188","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-44825","date":"2026-10-08","epss":0.02838,"percentile":0.86237}],"urls":["https://lists.apache.org/thread/5xg6xr99glocp3zsg9ht2zlbwlrst7ch","http://www.openwall.com/lists/oss-security/2026/05/29/6"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44825","description":"Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. \n\nAs an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords.\nThe future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.\n\nNot affected:\n  *  Clusters where bin/solr auth enable was not used to bootstrap BasicAuth\n  *  Clusters where template users have been assigned strong passwords after bootstrap"}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2887","versionConstraint":"<1.21.11||>=1.22.0-0,<1.22.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2887","fix":{"state":"fixed","versions":["1.21.11","1.22.4"],"available":[{"date":"2024-06-04","kind":"release","version":"1.21.11"},{"date":"2024-06-04","kind":"release","version":"1.22.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24790","date":"2026-10-08","epss":0.01952,"percentile":0.79639}],"risk":1.8348800000000003,"urls":["https://go.dev/issue/67680","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/590316","description":"The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms."},"relatedVulnerabilities":[{"id":"CVE-2024-24790","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24790","date":"2026-10-08","epss":0.01952,"percentile":0.79639}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/04/1","https://go.dev/cl/590316","https://go.dev/issue/67680","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ","https://pkg.go.dev/vuln/GO-2024-2887","https://security.netapp.com/advisory/ntap-20240905-0002/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24790","description":"The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4341","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4341","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"risk":1.7445,"urls":["https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736712","description":"The net/url package does not set a limit on the number of query parameters in a query.\n\nWhile the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61726","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"urls":["https://go.dev/cl/736712","https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4341","https://access.redhat.com/errata/RHSA-2026:10096","https://access.redhat.com/errata/RHSA-2026:10104","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:11408","https://access.redhat.com/errata/RHSA-2026:11414","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13542","https://access.redhat.com/errata/RHSA-2026:13548","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:15984","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17446","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17595","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:18913","https://access.redhat.com/errata/RHSA-2026:19013","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26420","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2706","https://access.redhat.com/errata/RHSA-2026:2708","https://access.redhat.com/errata/RHSA-2026:2709","https://access.redhat.com/errata/RHSA-2026:2754","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:2914","https://access.redhat.com/errata/RHSA-2026:2920","https://access.redhat.com/errata/RHSA-2026:3035","https://access.redhat.com/errata/RHSA-2026:3040","https://access.redhat.com/errata/RHSA-2026:3089","https://access.redhat.com/errata/RHSA-2026:3092","https://access.redhat.com/errata/RHSA-2026:3184","https://access.redhat.com/errata/RHSA-2026:3186","https://access.redhat.com/errata/RHSA-2026:3187","https://access.redhat.com/errata/RHSA-2026:3188","https://access.redhat.com/errata/RHSA-2026:3192","https://access.redhat.com/errata/RHSA-2026:3193","https://access.redhat.com/errata/RHSA-2026:3291","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:3297","https://access.redhat.com/errata/RHSA-2026:3298","https://access.redhat.com/errata/RHSA-2026:3336","https://access.redhat.com/errata/RHSA-2026:3337","https://access.redhat.com/errata/RHSA-2026:3340","https://access.redhat.com/errata/RHSA-2026:3341","https://access.redhat.com/errata/RHSA-2026:3343","https://access.redhat.com/errata/RHSA-2026:3391","https://access.redhat.com/errata/RHSA-2026:3416","https://access.redhat.com/errata/RHSA-2026:3427","https://access.redhat.com/errata/RHSA-2026:3459","https://access.redhat.com/errata/RHSA-2026:3468","https://access.redhat.com/errata/RHSA-2026:3469","https://access.redhat.com/errata/RHSA-2026:3470","https://access.redhat.com/errata/RHSA-2026:3471","https://access.redhat.com/errata/RHSA-2026:3472","https://access.redhat.com/errata/RHSA-2026:3473","https://access.redhat.com/errata/RHSA-2026:3489","https://access.redhat.com/errata/RHSA-2026:3506","https://access.redhat.com/errata/RHSA-2026:3556","https://access.redhat.com/errata/RHSA-2026:3559","https://access.redhat.com/errata/RHSA-2026:3668","https://access.redhat.com/errata/RHSA-2026:3669","https://access.redhat.com/errata/RHSA-2026:36873","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/errata/RHSA-2026:3699","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:3752","https://access.redhat.com/errata/RHSA-2026:3753","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3812","https://access.redhat.com/errata/RHSA-2026:3813","https://access.redhat.com/errata/RHSA-2026:3814","https://access.redhat.com/errata/RHSA-2026:3815","https://access.redhat.com/errata/RHSA-2026:3816","https://access.redhat.com/errata/RHSA-2026:3817","https://access.redhat.com/errata/RHSA-2026:3818","https://access.redhat.com/errata/RHSA-2026:3820","https://access.redhat.com/errata/RHSA-2026:3821","https://access.redhat.com/errata/RHSA-2026:3822","https://access.redhat.com/errata/RHSA-2026:3831","https://access.redhat.com/errata/RHSA-2026:3833","https://access.redhat.com/errata/RHSA-2026:3835","https://access.redhat.com/errata/RHSA-2026:3836","https://access.redhat.com/errata/RHSA-2026:3838","https://access.redhat.com/errata/RHSA-2026:3839","https://access.redhat.com/errata/RHSA-2026:3840","https://access.redhat.com/errata/RHSA-2026:3841","https://access.redhat.com/errata/RHSA-2026:3843","https://access.redhat.com/errata/RHSA-2026:3854","https://access.redhat.com/errata/RHSA-2026:3855","https://access.redhat.com/errata/RHSA-2026:3856","https://access.redhat.com/errata/RHSA-2026:3864","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3875","https://access.redhat.com/errata/RHSA-2026:3879","https://access.redhat.com/errata/RHSA-2026:3880","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3898","https://access.redhat.com/errata/RHSA-2026:3905","https://access.redhat.com/errata/RHSA-2026:3906","https://access.redhat.com/errata/RHSA-2026:3928","https://access.redhat.com/errata/RHSA-2026:3929","https://access.redhat.com/errata/RHSA-2026:3930","https://access.redhat.com/errata/RHSA-2026:3931","https://access.redhat.com/errata/RHSA-2026:3932","https://access.redhat.com/errata/RHSA-2026:3958","https://access.redhat.com/errata/RHSA-2026:3959","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:3970","https://access.redhat.com/errata/RHSA-2026:3971","https://access.redhat.com/errata/RHSA-2026:3972","https://access.redhat.com/errata/RHSA-2026:3973","https://access.redhat.com/errata/RHSA-2026:3974","https://access.redhat.com/errata/RHSA-2026:3977","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:3985","https://access.redhat.com/errata/RHSA-2026:40924","https://access.redhat.com/errata/RHSA-2026:4164","https://access.redhat.com/errata/RHSA-2026:4166","https://access.redhat.com/errata/RHSA-2026:4170","https://access.redhat.com/errata/RHSA-2026:4174","https://access.redhat.com/errata/RHSA-2026:4177","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:4211","https://access.redhat.com/errata/RHSA-2026:4220","https://access.redhat.com/errata/RHSA-2026:4256","https://access.redhat.com/errata/RHSA-2026:4264","https://access.redhat.com/errata/RHSA-2026:4267","https://access.redhat.com/errata/RHSA-2026:4270","https://access.redhat.com/errata/RHSA-2026:4276","https://access.redhat.com/errata/RHSA-2026:4434","https://access.redhat.com/errata/RHSA-2026:4435","https://access.redhat.com/errata/RHSA-2026:4460","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:4498","https://access.redhat.com/errata/RHSA-2026:4500","https://access.redhat.com/errata/RHSA-2026:4510","https://access.redhat.com/errata/RHSA-2026:4511","https://access.redhat.com/errata/RHSA-2026:4672","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:4753","https://access.redhat.com/errata/RHSA-2026:4892","https://access.redhat.com/errata/RHSA-2026:4901","https://access.redhat.com/errata/RHSA-2026:4907","https://access.redhat.com/errata/RHSA-2026:4939","https://access.redhat.com/errata/RHSA-2026:4942","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:4952","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5022","https://access.redhat.com/errata/RHSA-2026:5030","https://access.redhat.com/errata/RHSA-2026:5031","https://access.redhat.com/errata/RHSA-2026:5076","https://access.redhat.com/errata/RHSA-2026:5077","https://access.redhat.com/errata/RHSA-2026:5078","https://access.redhat.com/errata/RHSA-2026:5079","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:5129","https://access.redhat.com/errata/RHSA-2026:5130","https://access.redhat.com/errata/RHSA-2026:5131","https://access.redhat.com/errata/RHSA-2026:5132","https://access.redhat.com/errata/RHSA-2026:5145","https://access.redhat.com/errata/RHSA-2026:5146","https://access.redhat.com/errata/RHSA-2026:5168","https://access.redhat.com/errata/RHSA-2026:5327","https://access.redhat.com/errata/RHSA-2026:5394","https://access.redhat.com/errata/RHSA-2026:5439","https://access.redhat.com/errata/RHSA-2026:5444","https://access.redhat.com/errata/RHSA-2026:5447","https://access.redhat.com/errata/RHSA-2026:5452","https://access.redhat.com/errata/RHSA-2026:5461","https://access.redhat.com/errata/RHSA-2026:5463","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5533","https://access.redhat.com/errata/RHSA-2026:5544","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:5636","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:5645","https://access.redhat.com/errata/RHSA-2026:5649","https://access.redhat.com/errata/RHSA-2026:5665","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:5807","https://access.redhat.com/errata/RHSA-2026:5851","https://access.redhat.com/errata/RHSA-2026:5852","https://access.redhat.com/errata/RHSA-2026:5853","https://access.redhat.com/errata/RHSA-2026:5948","https://access.redhat.com/errata/RHSA-2026:5950","https://access.redhat.com/errata/RHSA-2026:5952","https://access.redhat.com/errata/RHSA-2026:5968","https://access.redhat.com/errata/RHSA-2026:6184","https://access.redhat.com/errata/RHSA-2026:6192","https://access.redhat.com/errata/RHSA-2026:6226","https://access.redhat.com/errata/RHSA-2026:6251","https://access.redhat.com/errata/RHSA-2026:6277","https://access.redhat.com/errata/RHSA-2026:6278","https://access.redhat.com/errata/RHSA-2026:6428","https://access.redhat.com/errata/RHSA-2026:6429","https://access.redhat.com/errata/RHSA-2026:6497","https://access.redhat.com/errata/RHSA-2026:6554","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:6567","https://access.redhat.com/errata/RHSA-2026:6568","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:7052","https://access.redhat.com/errata/RHSA-2026:7249","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7676","https://access.redhat.com/errata/RHSA-2026:7854","https://access.redhat.com/errata/RHSA-2026:7942","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8218","https://access.redhat.com/errata/RHSA-2026:8229","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8431","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9848","https://access.redhat.com/security/cve/CVE-2025-61726","https://bugzilla.redhat.com/show_bug.cgi?id=2434432","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61726","description":"The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."}]},{"artifact":{"id":"186e8c2634905bf8","cpes":["cpe:2.3:a:apache:commons-beanutils:1.9.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_beanutils:1.9.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:1.9.4:*:*:*:*:*:*:*"],"name":"commons-beanutils","purl":"pkg:maven/commons-beanutils/commons-beanutils@1.9.4","type":"java-archive","version":"1.9.4","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"commons-beanutils","virtualPath":"/opt/solr-10.0.0/cross-dc-manager/lib/commons-beanutils-1.9.4.jar","manifestName":"","pomArtifactID":"commons-beanutils","archiveDigests":[{"value":"d52b9abcd97f38c81342bb7e7ae1eee9b73cba51","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/cross-dc-manager/lib/commons-beanutils-1.9.4.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/cross-dc-manager/lib/commons-beanutils-1.9.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wxr5-93ph-8wr9","versionConstraint":">=1.0,<=1.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"commons-beanutils:commons-beanutils","version":"1.9.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wxr5-93ph-8wr9","fix":{"state":"fixed","versions":["1.11.0"],"available":[{"date":"2025-05-29","kind":"first-observed","version":"1.11.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48734","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-48734","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-48734","date":"2026-10-08","epss":0.01825,"percentile":0.78153}],"risk":1.487375,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48734","https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9","https://github.com/apache/commons-beanutils/commit/bd20740da25b69552ddef8523beec0837297eaf9","http://www.openwall.com/lists/oss-security/2025/05/28/6","https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wxr5-93ph-8wr9","description":"Apache Commons Improper Access Control vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2025-48734","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48734","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-48734","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-48734","date":"2026-10-08","epss":0.01825,"percentile":0.78153}],"urls":["https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9","http://www.openwall.com/lists/oss-security/2025/05/28/6","https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48734","description":"Improper Access Control vulnerability in Apache Commons.\n\n\n\nA special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.\n\n\n\n\n\nReleases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().\nStarting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user's guide and the unit tests.\n\nThis issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils\n\n 1.x are recommended to upgrade to version 1.11.0, which fixes the issue.\n\n\nUsers of the artifact org.apache.commons:commons-beanutils2\n\n 2.x are recommended to upgrade to version 2.0.0-M2, which fixes the issue."}]},{"artifact":{"id":"68103e7c5a4150d6","cpes":["cpe:2.3:a:apache:opennlp-tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp_tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:tools:2.5.6:*:*:*:*:*:*:*"],"name":"opennlp-tools","purl":"pkg:maven/org.apache.opennlp/opennlp-tools@2.5.6","type":"java-archive","version":"2.5.6","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.opennlp","virtualPath":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","manifestName":"","pomArtifactID":"opennlp-tools","archiveDigests":[{"value":"9d5d38502b8c16d08ae4990f105a65893da099a1","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cx4m-2p55-rw7j","versionConstraint":">=2.0.0,<2.5.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.opennlp:opennlp-tools","version":"2.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cx4m-2p55-rw7j","fix":{"state":"fixed","versions":["2.5.9"],"available":[{"date":"2026-05-09","kind":"first-observed","version":"2.5.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42027","cwe":"CWE-470","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42027","cwe":"CWE-502","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42027","date":"2026-10-08","epss":0.01271,"percentile":0.68969}],"risk":1.1947400000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-42027","https://lists.apache.org/thread/ltlo4powjfc0w2w2yyl1o5tc7q1gcb2y","http://www.openwall.com/lists/oss-security/2026/05/01/20","https://access.redhat.com/security/cve/CVE-2026-42027","https://bugzilla.redhat.com/show_bug.cgi?id=2466527","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42027.json","https://access.redhat.com/errata/RHSA-2026:65126"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cx4m-2p55-rw7j","description":"Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest"},"relatedVulnerabilities":[{"id":"CVE-2026-42027","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42027","cwe":"CWE-470","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42027","cwe":"CWE-502","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42027","date":"2026-10-08","epss":0.01271,"percentile":0.68969}],"urls":["https://lists.apache.org/thread/ltlo4powjfc0w2w2yyl1o5tc7q1gcb2y","http://www.openwall.com/lists/oss-security/2026/05/01/20","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-42027","https://bugzilla.redhat.com/show_bug.cgi?id=2466527","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42027.json","https://github.com/apache/opennlp/releases#release-opennlp-1.9.5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42027","description":"Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader\n\n\n\n\n\nVersions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3\n\n\n\n\n\nDescription: \n\nThe ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced from the manifest.properties entry of a model archive. The existing isAssignableFrom check correctly rejects classes that are not subtypes of the expected extension interface (BaseToolFactory for factory=, ArtifactSerializer for serializer-class-*), but the check runs after Class.forName() has already loaded and initialized the named class. \n\nClass.forName() with default initialization semantics executes the target class's static initializer before returning, so an attacker who can supply a crafted model archive can cause the static initializer of any class on the classpath to run during model loading, regardless of whether that class passes the subsequent type check. \n\nExploitation requires a class with attacker-useful side effects in its static initializer (for example, JNDI lookup, outbound network I/O, or filesystem access) to be present on the classpath, so this is not a drop-in remote code execution; however, the attack surface grows as third-party model distribution becomes more common (community model repositories, Hugging Face-style sharing), where users routinely load model files from origins they do not control. A secondary, narrower vector affects deployments that ship legitimate BaseToolFactory or ArtifactSerializer subclasses with side-effecting no-arg constructors: a malicious manifest can name such a class and force its constructor to run during model load.\n\n\n\n\n\nMitigation: \n\n\n\n  *  2.x users should upgrade to 2.5.9. \n  *  3.x users should upgrade to 3.0.0-M3. \n\n\n\n\nNote: The fix introduces a package-prefix allowlist that is consulted before Class.forName() is invoked, so the static initializer of a disallowed class is never executed. Classes under the opennlp. prefix remain permitted by default. Deployments that load models referencing factories or serializers outside opennlp.* must opt those packages in, either programmatically via ExtensionLoader.registerAllowedPackage(String) before the first model load, or by setting the OPENNLP_EXT_ALLOWED_PACKAGES system property to a comma-separated list of allowed package prefixes. \n\nUsers who cannot upgrade immediately should ensure that all model files are sourced from trusted origins and should audit their classpath for classes with side-effecting static initializers or constructors, particularly any that perform JNDI lookups, network requests, or filesystem operations during class initialization."}]},{"artifact":{"id":"39bfcc38eb1510d2","cpes":["cpe:2.3:a:apache:opennlp-tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp_tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:tools:2.5.6:*:*:*:*:*:*:*"],"name":"opennlp-tools","purl":"pkg:maven/org.apache.opennlp/opennlp-tools@2.5.6","type":"java-archive","version":"2.5.6","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.opennlp","virtualPath":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","manifestName":"","pomArtifactID":"opennlp-tools","archiveDigests":[{"value":"9d5d38502b8c16d08ae4990f105a65893da099a1","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cx4m-2p55-rw7j","versionConstraint":">=2.0.0,<2.5.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.opennlp:opennlp-tools","version":"2.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cx4m-2p55-rw7j","fix":{"state":"fixed","versions":["2.5.9"],"available":[{"date":"2026-05-09","kind":"first-observed","version":"2.5.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42027","cwe":"CWE-470","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42027","cwe":"CWE-502","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42027","date":"2026-10-08","epss":0.01271,"percentile":0.68969}],"risk":1.1947400000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-42027","https://lists.apache.org/thread/ltlo4powjfc0w2w2yyl1o5tc7q1gcb2y","http://www.openwall.com/lists/oss-security/2026/05/01/20","https://access.redhat.com/security/cve/CVE-2026-42027","https://bugzilla.redhat.com/show_bug.cgi?id=2466527","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42027.json","https://access.redhat.com/errata/RHSA-2026:65126"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cx4m-2p55-rw7j","description":"Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest"},"relatedVulnerabilities":[{"id":"CVE-2026-42027","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42027","cwe":"CWE-470","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42027","cwe":"CWE-502","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42027","date":"2026-10-08","epss":0.01271,"percentile":0.68969}],"urls":["https://lists.apache.org/thread/ltlo4powjfc0w2w2yyl1o5tc7q1gcb2y","http://www.openwall.com/lists/oss-security/2026/05/01/20","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/security/cve/CVE-2026-42027","https://bugzilla.redhat.com/show_bug.cgi?id=2466527","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42027.json","https://github.com/apache/opennlp/releases#release-opennlp-1.9.5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42027","description":"Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader\n\n\n\n\n\nVersions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3\n\n\n\n\n\nDescription: \n\nThe ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its no-arg constructor, with the class name sourced from the manifest.properties entry of a model archive. The existing isAssignableFrom check correctly rejects classes that are not subtypes of the expected extension interface (BaseToolFactory for factory=, ArtifactSerializer for serializer-class-*), but the check runs after Class.forName() has already loaded and initialized the named class. \n\nClass.forName() with default initialization semantics executes the target class's static initializer before returning, so an attacker who can supply a crafted model archive can cause the static initializer of any class on the classpath to run during model loading, regardless of whether that class passes the subsequent type check. \n\nExploitation requires a class with attacker-useful side effects in its static initializer (for example, JNDI lookup, outbound network I/O, or filesystem access) to be present on the classpath, so this is not a drop-in remote code execution; however, the attack surface grows as third-party model distribution becomes more common (community model repositories, Hugging Face-style sharing), where users routinely load model files from origins they do not control. A secondary, narrower vector affects deployments that ship legitimate BaseToolFactory or ArtifactSerializer subclasses with side-effecting no-arg constructors: a malicious manifest can name such a class and force its constructor to run during model load.\n\n\n\n\n\nMitigation: \n\n\n\n  *  2.x users should upgrade to 2.5.9. \n  *  3.x users should upgrade to 3.0.0-M3. \n\n\n\n\nNote: The fix introduces a package-prefix allowlist that is consulted before Class.forName() is invoked, so the static initializer of a disallowed class is never executed. Classes under the opennlp. prefix remain permitted by default. Deployments that load models referencing factories or serializers outside opennlp.* must opt those packages in, either programmatically via ExtensionLoader.registerAllowedPackage(String) before the first model load, or by setting the OPENNLP_EXT_ALLOWED_PACKAGES system property to a comma-separated list of allowed package prefixes. \n\nUsers who cannot upgrade immediately should ensure that all model files are sourced from trusted origins and should audit their classpath for classes with side-effecting static initializers or constructors, particularly any that perform JNDI lookups, network requests, or filesystem operations during class initialization."}]},{"artifact":{"id":"1facc3e875c221a8","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"311ea62f27b26685b306dc24c4bbf765bc1950d9","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x4gw-5cx5-pgmh","versionConstraint":">=4.2.0.Final,<=4.2.14.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-x4gw-5cx5-pgmh","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-09","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45416","date":"2026-10-08","epss":0.01576,"percentile":0.74713}],"risk":1.1820000000000002,"urls":["https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-45416"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x4gw-5cx5-pgmh","description":"Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes"},"relatedVulnerabilities":[{"id":"CVE-2026-45416","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45416","date":"2026-10-08","epss":0.01576,"percentile":0.74713}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-45416","https://bugzilla.redhat.com/show_bug.cgi?id=2488391","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45416.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45416","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2963","versionConstraint":"<1.21.12||>=1.22.0-0,<1.22.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2963","fix":{"state":"fixed","versions":["1.21.12","1.22.5"],"available":[{"date":"2024-07-02","kind":"release","version":"1.21.12"},{"date":"2024-07-02","kind":"release","version":"1.22.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24791","date":"2026-10-08","epss":0.01414,"percentile":0.71922}],"risk":1.0605,"urls":["https://go.dev/issue/67555","https://groups.google.com/g/golang-dev/c/t0rK-qHBqzY/m/6MMoAZkMAgAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/591255","description":"The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an \"Expect: 100-continue\" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail.\n\nAn attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending \"Expect: 100-continue\" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail."},"relatedVulnerabilities":[{"id":"CVE-2024-24791","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24791","date":"2026-10-08","epss":0.01414,"percentile":0.71922}],"urls":["https://go.dev/cl/591255","https://go.dev/issue/67555","https://groups.google.com/g/golang-dev/c/t0rK-qHBqzY/m/6MMoAZkMAgAJ","https://pkg.go.dev/vuln/GO-2024-2963","https://security.netapp.com/advisory/ntap-20241004-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24791","description":"The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an \"Expect: 100-continue\" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending \"Expect: 100-continue\" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail."}]},{"artifact":{"id":"1facc3e875c221a8","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"311ea62f27b26685b306dc24c4bbf765bc1950d9","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3qp7-7mw8-wx86","versionConstraint":">=4.2.0.Final,<=4.2.14.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3qp7-7mw8-wx86","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-09","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44249","date":"2026-10-08","epss":0.01291,"percentile":0.69378}],"risk":1.00698,"urls":["https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-44249"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3qp7-7mw8-wx86","description":"Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking"},"relatedVulnerabilities":[{"id":"CVE-2026-44249","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44249","date":"2026-10-08","epss":0.01291,"percentile":0.69378}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-44249","https://bugzilla.redhat.com/show_bug.cgi?id=2488081","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44249","description":"Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"cfbd19c60d7ed087","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:http:12.0.27:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@12.0.27","type":"java-archive","version":"12.0.27","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/opt/solr-10.0.0/server/lib/ext/jetty-http-12.0.27.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"a87f269dbac2a0aae6d9020b26e853bbe6bb8b8e","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/jetty-http-12.0.27.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/jetty-http-12.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.33"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-355h-qmc2-wpwf","versionConstraint":">=12.0.0,<=12.0.32 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"12.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-355h-qmc2-wpwf","fix":{"state":"fixed","versions":["12.0.33"],"available":[{"date":"2026-04-15","kind":"first-observed","version":"12.0.33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-2332","date":"2026-10-08","epss":0.01305,"percentile":0.69668}],"risk":0.972225,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://nvd.nist.gov/vuln/detail/CVE-2026-2332","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://w4ke.info/2025/06/18/funky-chunks.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://access.redhat.com/security/cve/CVE-2026-2332","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:10175"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-355h-qmc2-wpwf","description":"Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-2332","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-2332","date":"2026-10-08","epss":0.01305,"percentile":0.69668}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-2332","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332","description":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request."}]},{"artifact":{"id":"bbc5cc41b592ab13","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"55b556602dd5ae7adf7a0ef4720195138018a623","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.11.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w9fj-cfpg-grvv","versionConstraint":">=4.2.0.Alpha1,<4.2.10.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-w9fj-cfpg-grvv","fix":{"state":"fixed","versions":["4.2.11.Final"],"available":[{"date":"2026-03-27","kind":"first-observed","version":"4.2.11.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33871","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33871","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33871","date":"2026-10-08","epss":0.012,"percentile":0.6727}],"risk":0.972,"urls":["https://github.com/netty/netty/security/advisories/GHSA-w9fj-cfpg-grvv","https://nvd.nist.gov/vuln/detail/CVE-2026-33871"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w9fj-cfpg-grvv","description":"Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-33871","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33871","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33871","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33871","date":"2026-10-08","epss":0.012,"percentile":0.6727}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-w9fj-cfpg-grvv","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:17789","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:22619","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:7109","https://access.redhat.com/errata/RHSA-2026:7380","https://access.redhat.com/errata/RHSA-2026:8159","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-33871","https://bugzilla.redhat.com/show_bug.cgi?id=2452456","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33871.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33871","description":"Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue."}]},{"artifact":{"id":"56d5f316ec5e4544","cpes":["cpe:2.3:a:apache:zookeeper:3.9.4:*:*:*:*:*:*:*"],"name":"zookeeper","purl":"pkg:maven/org.apache.zookeeper/zookeeper@3.9.4","type":"java-archive","version":"3.9.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.zookeeper","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/zookeeper-3.9.4.jar","manifestName":"","pomArtifactID":"zookeeper","archiveDigests":[{"value":"5ab49d76fcac9a33c255b0585bc1fc92e24166db","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/zookeeper-3.9.4.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/zookeeper-3.9.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.9.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-crhr-qqj8-rpxc","versionConstraint":">=3.9.0,<3.9.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.zookeeper:zookeeper","version":"3.9.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-crhr-qqj8-rpxc","fix":{"state":"fixed","versions":["3.9.5"],"available":[{"date":"2026-03-10","kind":"first-observed","version":"3.9.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24308","cwe":"CWE-532","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24308","cwe":"CWE-117","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24308","date":"2026-10-08","epss":0.01197,"percentile":0.67207}],"risk":0.9695699999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-24308","https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdr","http://www.openwall.com/lists/oss-security/2026/03/07/5","https://github.com/apache/zookeeper/releases/tag/release-3.8.6","https://github.com/apache/zookeeper/releases/tag/release-3.9.5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-crhr-qqj8-rpxc","description":"Apache ZooKeeper has improper handling of configuration values"},"relatedVulnerabilities":[{"id":"CVE-2026-24308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24308","cwe":"CWE-532","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24308","cwe":"CWE-117","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24308","date":"2026-10-08","epss":0.01197,"percentile":0.67207}],"urls":["https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdr","http://www.openwall.com/lists/oss-security/2026/03/07/5","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-24308","https://bugzilla.redhat.com/show_bug.cgi?id=2445451","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24308.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24308","description":"Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"risk":0.95628,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)"},"relatedVulnerabilities":[{"id":"CVE-2026-54513","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4337","versionConstraint":"<1.24.13||>=1.25.0-0,<1.25.7||>=1.26.0-rc.1,<1.26.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4337","fix":{"state":"fixed","versions":["1.24.13","1.25.7","1.26.0-rc.3"],"available":[{"date":"2026-02-04","kind":"release","version":"1.24.13"},{"date":"2026-02-04","kind":"release","version":"1.25.7"},{"date":"2026-02-04","kind":"release","version":"1.26.0-rc.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"risk":0.8692500000000001,"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-68121","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217","https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","https://pkg.go.dev/vuln/GO-2026-4337"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68121","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-3106","versionConstraint":"<1.22.7||>=1.23.0-0,<1.23.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-3106","fix":{"state":"fixed","versions":["1.22.7","1.23.1"],"available":[{"date":"2024-09-05","kind":"release","version":"1.22.7"},{"date":"2024-09-05","kind":"release","version":"1.23.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34156","date":"2026-10-08","epss":0.01127,"percentile":0.65326}],"risk":0.84525,"urls":["https://go.dev/issue/69139","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/611239","description":"Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635."},"relatedVulnerabilities":[{"id":"CVE-2024-34156","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34156","date":"2026-10-08","epss":0.01127,"percentile":0.65326}],"urls":["https://go.dev/cl/611239","https://go.dev/issue/69139","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk","https://pkg.go.dev/vuln/GO-2024-3106","https://security.netapp.com/advisory/ntap-20240926-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34156","description":"Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635."}]},{"artifact":{"id":"68103e7c5a4150d6","cpes":["cpe:2.3:a:apache:opennlp-tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp_tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:tools:2.5.6:*:*:*:*:*:*:*"],"name":"opennlp-tools","purl":"pkg:maven/org.apache.opennlp/opennlp-tools@2.5.6","type":"java-archive","version":"2.5.6","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.opennlp","virtualPath":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","manifestName":"","pomArtifactID":"opennlp-tools","archiveDigests":[{"value":"9d5d38502b8c16d08ae4990f105a65893da099a1","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-659w-93r5-9j6m","versionConstraint":"<2.5.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.opennlp:opennlp-tools","version":"2.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-659w-93r5-9j6m","fix":{"state":"fixed","versions":["2.5.9"],"available":[{"date":"2026-05-09","kind":"first-observed","version":"2.5.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42440","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42440","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42440","date":"2026-10-08","epss":0.01065,"percentile":0.63645}],"risk":0.79875,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-42440","https://lists.apache.org/thread/s8xlkx1gqbxfsq48py5h6jphjvgqp1jo","http://www.openwall.com/lists/oss-security/2026/05/01/21"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-659w-93r5-9j6m","description":"Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation"},"relatedVulnerabilities":[{"id":"CVE-2026-42440","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42440","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42440","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42440","date":"2026-10-08","epss":0.01065,"percentile":0.63645}],"urls":["https://lists.apache.org/thread/s8xlkx1gqbxfsq48py5h6jphjvgqp1jo","http://www.openwall.com/lists/oss-security/2026/05/01/21","https://access.redhat.com/security/cve/CVE-2026-42440","https://bugzilla.redhat.com/show_bug.cgi?id=2466494","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42440.json","https://github.com/apache/opennlp/releases#release-opennlp-1.9.5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42440","description":"OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader \n\nVersions Affected: \n\nbefore 1.9.5\nbefore 2.5.9\n\nbefore 3.0.0-M3 \n\nDescription:\n\n\nThe AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field from a binary model stream and pass that value directly to an array allocation (new String[numOutcomes], new int[numOCTypes][], new String[NUM_PREDS]) without validating that the value is non-negative or within a reasonable bound. The count is therefore fully attacker-controlled when the model file originates from an untrusted source.\n\n\nA crafted .bin model file in which any of these count fields is set to Integer.MAX_VALUE (or any value large enough to exhaust the available heap) triggers an OutOfMemoryError at the array allocation itself, before the corresponding label or pattern data is consumed from the stream. The error occurs very early in deserialization: for a GIS model, getOutcomes() is reached after only the model-type string, the correction constant, and the correction parameter have been read; so the attacker pays no meaningful size cost to weaponize a payload, and a single small file can crash a JVM that loads it. Any code path that deserializes a .bin model is affected, including direct use of GenericModelReader and any higher-level component that delegates to it during model load.\n\n\nThe practical impact is denial of service against processes that load model files from untrusted or semi-trusted origins.  \n\n\nMitigation:\n\n\n\n  *  2.x users should upgrade to 2.5.9.\n\n  *  3.x users should upgrade to 3.0.0-M3.\n\n\n\n\nNote: The fix introduces an upper bound on each of the three count fields, checked before array allocation; counts that are negative or exceed the bound cause an IllegalArgumentException to be thrown and the read to fail fast with no large allocation. The default bound is 10,000,000, which is well above the entry counts of legitimate OpenNLP models but far below any value that would threaten heap exhaustion. Deployments that legitimately need to load models with more entries than the default can raise the limit at JVM startup by setting the OPENNLP_MAX_ENTRIES system property to the desired positive integer (e.g. -DOPENNLP_MAX_ENTRIES=50000000); invalid or non-positive values fall back to the default.\n\n\nUsers who cannot upgrade immediately should treat all .bin model files as untrusted input unless their provenance is verified, and should avoid loading models supplied by end users or fetched from third-party repositories without integrity checks."}]},{"artifact":{"id":"39bfcc38eb1510d2","cpes":["cpe:2.3:a:apache:opennlp-tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp_tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:tools:2.5.6:*:*:*:*:*:*:*"],"name":"opennlp-tools","purl":"pkg:maven/org.apache.opennlp/opennlp-tools@2.5.6","type":"java-archive","version":"2.5.6","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.opennlp","virtualPath":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","manifestName":"","pomArtifactID":"opennlp-tools","archiveDigests":[{"value":"9d5d38502b8c16d08ae4990f105a65893da099a1","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-659w-93r5-9j6m","versionConstraint":"<2.5.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.opennlp:opennlp-tools","version":"2.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-659w-93r5-9j6m","fix":{"state":"fixed","versions":["2.5.9"],"available":[{"date":"2026-05-09","kind":"first-observed","version":"2.5.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42440","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42440","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42440","date":"2026-10-08","epss":0.01065,"percentile":0.63645}],"risk":0.79875,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-42440","https://lists.apache.org/thread/s8xlkx1gqbxfsq48py5h6jphjvgqp1jo","http://www.openwall.com/lists/oss-security/2026/05/01/21"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-659w-93r5-9j6m","description":"Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation"},"relatedVulnerabilities":[{"id":"CVE-2026-42440","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42440","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-42440","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42440","date":"2026-10-08","epss":0.01065,"percentile":0.63645}],"urls":["https://lists.apache.org/thread/s8xlkx1gqbxfsq48py5h6jphjvgqp1jo","http://www.openwall.com/lists/oss-security/2026/05/01/21","https://access.redhat.com/security/cve/CVE-2026-42440","https://bugzilla.redhat.com/show_bug.cgi?id=2466494","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42440.json","https://github.com/apache/opennlp/releases#release-opennlp-1.9.5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42440","description":"OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader \n\nVersions Affected: \n\nbefore 1.9.5\nbefore 2.5.9\n\nbefore 3.0.0-M3 \n\nDescription:\n\n\nThe AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field from a binary model stream and pass that value directly to an array allocation (new String[numOutcomes], new int[numOCTypes][], new String[NUM_PREDS]) without validating that the value is non-negative or within a reasonable bound. The count is therefore fully attacker-controlled when the model file originates from an untrusted source.\n\n\nA crafted .bin model file in which any of these count fields is set to Integer.MAX_VALUE (or any value large enough to exhaust the available heap) triggers an OutOfMemoryError at the array allocation itself, before the corresponding label or pattern data is consumed from the stream. The error occurs very early in deserialization: for a GIS model, getOutcomes() is reached after only the model-type string, the correction constant, and the correction parameter have been read; so the attacker pays no meaningful size cost to weaponize a payload, and a single small file can crash a JVM that loads it. Any code path that deserializes a .bin model is affected, including direct use of GenericModelReader and any higher-level component that delegates to it during model load.\n\n\nThe practical impact is denial of service against processes that load model files from untrusted or semi-trusted origins.  \n\n\nMitigation:\n\n\n\n  *  2.x users should upgrade to 2.5.9.\n\n  *  3.x users should upgrade to 3.0.0-M3.\n\n\n\n\nNote: The fix introduces an upper bound on each of the three count fields, checked before array allocation; counts that are negative or exceed the bound cause an IllegalArgumentException to be thrown and the read to fail fast with no large allocation. The default bound is 10,000,000, which is well above the entry counts of legitimate OpenNLP models but far below any value that would threaten heap exhaustion. Deployments that legitimately need to load models with more entries than the default can raise the limit at JVM startup by setting the OPENNLP_MAX_ENTRIES system property to the desired positive integer (e.g. -DOPENNLP_MAX_ENTRIES=50000000); invalid or non-positive values fall back to the default.\n\n\nUsers who cannot upgrade immediately should treat all .bin model files as untrusted input unless their provenance is verified, and should avoid loading models supplied by end users or fetched from third-party repositories without integrity checks."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f6hv-jmp6-3vwv","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f6hv-jmp6-3vwv","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42587","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42587","date":"2026-10-08","epss":0.01046,"percentile":0.63119}],"risk":0.7845000000000001,"urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://nvd.nist.gov/vuln/detail/CVE-2026-42587"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f6hv-jmp6-3vwv","description":"Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-42587","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42587","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42587","date":"2026-10-08","epss":0.01046,"percentile":0.63119}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-42587","https://bugzilla.redhat.com/show_bug.cgi?id=2477220","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42587.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42587","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"bbc5cc41b592ab13","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"55b556602dd5ae7adf7a0ef4720195138018a623","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f6hv-jmp6-3vwv","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f6hv-jmp6-3vwv","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42587","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42587","date":"2026-10-08","epss":0.01046,"percentile":0.63119}],"risk":0.7845000000000001,"urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://nvd.nist.gov/vuln/detail/CVE-2026-42587"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f6hv-jmp6-3vwv","description":"Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-42587","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42587","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42587","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42587","date":"2026-10-08","epss":0.01046,"percentile":0.63119}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-42587","https://bugzilla.redhat.com/show_bug.cgi?id=2477220","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42587.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42587","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-3107","versionConstraint":"<1.22.7||>=1.23.0-0,<1.23.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-3107","fix":{"state":"fixed","versions":["1.22.7","1.23.1"],"available":[{"date":"2024-09-05","kind":"release","version":"1.22.7"},{"date":"2024-09-05","kind":"release","version":"1.23.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34158","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34158","date":"2026-10-08","epss":0.01046,"percentile":0.63108}],"risk":0.7845000000000001,"urls":["https://go.dev/issue/69141","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/611240","description":"Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2024-34158","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34158","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34158","date":"2026-10-08","epss":0.01046,"percentile":0.63108}],"urls":["https://go.dev/cl/611240","https://go.dev/issue/69141","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk","https://pkg.go.dev/vuln/GO-2024-3107","https://security.netapp.com/advisory/ntap-20241004-0003/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34158","description":"Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.19.0,<=2.21.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"risk":0.7792200000000001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation"},"relatedVulnerabilities":[{"id":"CVE-2026-54512","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"68103e7c5a4150d6","cpes":["cpe:2.3:a:apache:opennlp-tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp_tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:tools:2.5.6:*:*:*:*:*:*:*"],"name":"opennlp-tools","purl":"pkg:maven/org.apache.opennlp/opennlp-tools@2.5.6","type":"java-archive","version":"2.5.6","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.opennlp","virtualPath":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","manifestName":"","pomArtifactID":"opennlp-tools","archiveDigests":[{"value":"9d5d38502b8c16d08ae4990f105a65893da099a1","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/langid/lib/opennlp-tools-2.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v8g-86x5-3vrc","versionConstraint":">=2.0.0,<2.5.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.opennlp:opennlp-tools","version":"2.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v8g-86x5-3vrc","fix":{"state":"fixed","versions":["2.5.9"],"available":[{"date":"2026-05-09","kind":"first-observed","version":"2.5.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-40682","date":"2026-10-08","epss":0.00844,"percentile":0.56685}],"risk":0.7638199999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-40682","https://lists.apache.org/thread/r6jpt0qr9nj67gqhppqg7jxf8vsbo0w6","http://www.openwall.com/lists/oss-security/2026/05/01/19","https://access.redhat.com/security/cve/CVE-2026-40682","https://bugzilla.redhat.com/show_bug.cgi?id=2466484","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40682.json"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v8g-86x5-3vrc","description":"Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-40682","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-40682","date":"2026-10-08","epss":0.00844,"percentile":0.56685}],"urls":["https://lists.apache.org/thread/r6jpt0qr9nj67gqhppqg7jxf8vsbo0w6","http://www.openwall.com/lists/oss-security/2026/05/01/19","https://access.redhat.com/security/cve/CVE-2026-40682","https://bugzilla.redhat.com/show_bug.cgi?id=2466484","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40682.json","https://github.com/apache/opennlp/releases#release-opennlp-1.9.5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40682","description":"XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor\n\n\nVersions Affected: before 2.5.9, before 3.0.0-M3\n\n\nDescription: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(InputStream, EntryInserter) is invoked, the only feature set on the XMLReader is namespace support — external entity resolution and DOCTYPE declarations remain fully enabled. An attacker who can supply a crafted dictionary file (e.g., a stop-word list or domain dictionary) containing a malicious DOCTYPE declaration can trigger local file disclosure via file:// entity references or server-side request forgery via http:// entity references during SAX parsing, before the application processes a single dictionary entry. This is inconsistent with the project's own XmlUtil.createSaxParser() helper, which correctly sets FEATURE_SECURE_PROCESSING and disallow-doctype-decl and is used by all other XML parsing paths in the codebase. The public Dictionary(InputStream) constructor delegates directly to this method and is the documented API for loading user-supplied dictionaries, making untrusted input a realistic scenario.\n\n\nMitigation: 2.x users should upgrade to 2.5.9. 3.x users should upgrade to 3.0.0-M3. Users who cannot upgrade immediately should ensure that all dictionary files are sourced from trusted origins and should consider wrapping the Dictionary(InputStream) constructor with input validation that rejects any XML containing a DOCTYPE declaration before it reaches the parser."}]},{"artifact":{"id":"39bfcc38eb1510d2","cpes":["cpe:2.3:a:apache:opennlp-tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp_tools:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:opennlp:2.5.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:tools:2.5.6:*:*:*:*:*:*:*"],"name":"opennlp-tools","purl":"pkg:maven/org.apache.opennlp/opennlp-tools@2.5.6","type":"java-archive","version":"2.5.6","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.opennlp","virtualPath":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","manifestName":"","pomArtifactID":"opennlp-tools","archiveDigests":[{"value":"9d5d38502b8c16d08ae4990f105a65893da099a1","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/analysis-extras/lib/opennlp-tools-2.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.5.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v8g-86x5-3vrc","versionConstraint":">=2.0.0,<2.5.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.opennlp:opennlp-tools","version":"2.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v8g-86x5-3vrc","fix":{"state":"fixed","versions":["2.5.9"],"available":[{"date":"2026-05-09","kind":"first-observed","version":"2.5.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-40682","date":"2026-10-08","epss":0.00844,"percentile":0.56685}],"risk":0.7638199999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-40682","https://lists.apache.org/thread/r6jpt0qr9nj67gqhppqg7jxf8vsbo0w6","http://www.openwall.com/lists/oss-security/2026/05/01/19","https://access.redhat.com/security/cve/CVE-2026-40682","https://bugzilla.redhat.com/show_bug.cgi?id=2466484","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40682.json"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v8g-86x5-3vrc","description":"Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-40682","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-40682","cwe":"CWE-611","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-40682","date":"2026-10-08","epss":0.00844,"percentile":0.56685}],"urls":["https://lists.apache.org/thread/r6jpt0qr9nj67gqhppqg7jxf8vsbo0w6","http://www.openwall.com/lists/oss-security/2026/05/01/19","https://access.redhat.com/security/cve/CVE-2026-40682","https://bugzilla.redhat.com/show_bug.cgi?id=2466484","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40682.json","https://github.com/apache/opennlp/releases#release-opennlp-1.9.5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40682","description":"XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor\n\n\nVersions Affected: before 2.5.9, before 3.0.0-M3\n\n\nDescription: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(InputStream, EntryInserter) is invoked, the only feature set on the XMLReader is namespace support — external entity resolution and DOCTYPE declarations remain fully enabled. An attacker who can supply a crafted dictionary file (e.g., a stop-word list or domain dictionary) containing a malicious DOCTYPE declaration can trigger local file disclosure via file:// entity references or server-side request forgery via http:// entity references during SAX parsing, before the application processes a single dictionary entry. This is inconsistent with the project's own XmlUtil.createSaxParser() helper, which correctly sets FEATURE_SECURE_PROCESSING and disallow-doctype-decl and is used by all other XML parsing paths in the codebase. The public Dictionary(InputStream) constructor delegates directly to this method and is the documented API for loading user-supplied dictionaries, making untrusted input a realistic scenario.\n\n\nMitigation: 2.x users should upgrade to 2.5.9. 3.x users should upgrade to 3.0.0-M3. Users who cannot upgrade immediately should ensure that all dictionary files are sourced from trusted origins and should consider wrapping the Dictionary(InputStream) constructor with input validation that rejects any XML containing a DOCTYPE declaration before it reaches the parser."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3563","versionConstraint":"<1.23.8||>=1.24.0-0,<1.24.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3563","fix":{"state":"fixed","versions":["1.23.8","1.24.2"],"available":[{"date":"2025-04-01","kind":"release","version":"1.23.8"},{"date":"2025-04-01","kind":"release","version":"1.24.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22871","date":"2026-10-08","epss":0.00811,"percentile":0.55659}],"risk":0.7339549999999999,"urls":["https://go.dev/issue/71988","https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/652998","description":"The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext."},"relatedVulnerabilities":[{"id":"CVE-2025-22871","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22871","date":"2026-10-08","epss":0.00811,"percentile":0.55659}],"urls":["https://go.dev/cl/652998","https://go.dev/issue/71988","https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk","https://pkg.go.dev/vuln/GO-2025-3563","http://www.openwall.com/lists/oss-security/2025/04/04/4","https://cert-portal.siemens.com/productcert/html/ssa-783943.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22871","description":"The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext."}]},{"artifact":{"id":"8ef1504da9b7bb58","cpes":["cpe:2.3:a:apache:log4j-core:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.25.3:*:*:*:*:*:*:*"],"name":"log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.25.3","type":"java-archive","version":"2.25.3","language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","manifestName":"","pomArtifactID":"log4j-core","archiveDigests":[{"value":"dd9c8ecba5c8dc5e1574804d0bfdc1ef155ad9ea","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pxv-7cmr-fjr4","versionConstraint":">=2.0-alpha1,<2.25.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.25.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3pxv-7cmr-fjr4","fix":{"state":"fixed","versions":["2.25.4"],"available":[{"date":"2026-04-11","kind":"first-observed","version":"2.25.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34480","date":"2026-10-08","epss":0.01187,"percentile":0.6694}],"risk":0.706265,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34480","https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pxv-7cmr-fjr4","description":"Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters"},"relatedVulnerabilities":[{"id":"CVE-2026-34480","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34480","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34480","date":"2026-10-08","epss":0.01187,"percentile":0.6694}],"urls":["https://github.com/apache/logging-log4j2/pull/4077","https://lists.apache.org/thread/5x0hcnng0chhghp6jgjdp3qmbbhfjzhb","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout","https://logging.apache.org/security.html#CVE-2026-34480","http://www.openwall.com/lists/oss-security/2026/04/10/9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34480","description":"Apache Log4j Core's  XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the  XML 1.0 specification https://www.w3.org/TR/xml/#charsets  producing invalid XML output whenever a log message or MDC value contains such characters.\n\nThe impact depends on the StAX implementation in use:\n\n  *  JRE built-in StAX: Forbidden characters are silently written to the output, producing malformed XML. Conforming parsers must reject such documents with a fatal error, which may cause downstream log-processing systems to drop the affected records.\n  *  Alternative StAX implementations (e.g.,  Woodstox https://github.com/FasterXML/woodstox , a transitive dependency of the Jackson XML Dataformat module): An exception is thrown during the logging call, and the log event is never delivered to its intended appender, only to Log4j's internal status logger.\n\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue by sanitizing forbidden characters before XML output."}]},{"artifact":{"id":"8ef1504da9b7bb58","cpes":["cpe:2.3:a:apache:log4j-core:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.25.3:*:*:*:*:*:*:*"],"name":"log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.25.3","type":"java-archive","version":"2.25.3","language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","manifestName":"","pomArtifactID":"log4j-core","archiveDigests":[{"value":"dd9c8ecba5c8dc5e1574804d0bfdc1ef155ad9ea","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-445c-vh5m-36rj","versionConstraint":">=2.21.0,<2.25.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.25.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-445c-vh5m-36rj","fix":{"state":"fixed","versions":["2.25.4"],"available":[{"date":"2026-04-14","kind":"first-observed","version":"2.25.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34478","cwe":"CWE-117","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-34478","cwe":"CWE-684","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34478","date":"2026-10-08","epss":0.01187,"percentile":0.6694}],"risk":0.706265,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34478","https://github.com/apache/logging-log4j2/pull/4074","https://lists.apache.org/thread/3k1clr2l6vkdnl4cbhjrnt1nyjvb5gwt","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout","https://logging.apache.org/security.html#CVE-2026-34478","http://www.openwall.com/lists/oss-security/2026/04/10/7"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-445c-vh5m-36rj","description":"Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility"},"relatedVulnerabilities":[{"id":"CVE-2026-34478","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34478","cwe":"CWE-117","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-34478","cwe":"CWE-684","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34478","date":"2026-10-08","epss":0.01187,"percentile":0.6694}],"urls":["https://github.com/apache/logging-log4j2/pull/4074","https://lists.apache.org/thread/3k1clr2l6vkdnl4cbhjrnt1nyjvb5gwt","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout","https://logging.apache.org/security.html#CVE-2026-34478","http://www.openwall.com/lists/oss-security/2026/04/10/7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34478","description":"Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.\n\nTwo distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:\n\n  *  The newLineEscape attribute was silently renamed, causing newline escaping to stop working for users of TCP framing (RFC 6587), exposing them to CRLF injection in log output.\n  *  The useTlsMessageFormat attribute was silently renamed, causing users of TLS framing (RFC 5425) to be silently downgraded to unframed TCP (RFC 6587), without newline escaping.\n\n\nUsers of the SyslogAppender are not affected, as its configuration attributes were not modified.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue."}]},{"artifact":{"id":"6968de471313031e","cpes":["cpe:2.3:a:apache:httpcore5-h2:5.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:httpcore5_h2:5.2:*:*:*:*:*:*:*"],"name":"httpcore5-h2","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.2","type":"java-archive","version":"5.2","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.httpcomponents.core5","virtualPath":"/opt/solr-10.0.0/modules/sql/lib/httpcore5-h2-5.2.jar","manifestName":"","pomArtifactID":"httpcore5-h2","archiveDigests":[{"value":"698bd8c759ccc7fd7398f3179ff45d0e5a7ccc16","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/sql/lib/httpcore5-h2-5.2.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/sql/lib/httpcore5-h2-5.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v3jc-474w-2wm6","versionConstraint":"<5.4.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.core5:httpcore5-h2","version":"5.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v3jc-474w-2wm6","fix":{"state":"fixed","versions":["5.4.3"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"5.4.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-54428","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54428","date":"2026-10-08","epss":0.0087,"percentile":0.57533}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54428","https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3","https://github.com/apache/httpcomponents-core/commit/1ea1239bbbe3442a8382a87279c0a8119a7e358e","https://github.com/apache/httpcomponents-core/commit/cc30ee058a7b10cbf4ad3dd6270ab6d1f6a74c49"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v3jc-474w-2wm6","description":"Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK"},"relatedVulnerabilities":[{"id":"CVE-2026-54428","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54428","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-54428","cwe":"CWE-770","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54428","date":"2026-10-08","epss":0.0087,"percentile":0.57533}],"urls":["https://lists.apache.org/thread/5zjp8vczvxq19pw2rvhs21q446bhl0sd","http://www.openwall.com/lists/oss-security/2026/07/01/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54428","description":"Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied."}]},{"artifact":{"id":"6400f578f286953e","cpes":["cpe:2.3:a:apache:httpcore5:5.2.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:core5:5.2.3:*:*:*:*:*:*:*"],"name":"httpcore5","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.2.3","type":"java-archive","version":"5.2.3","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.httpcomponents.core5","virtualPath":"/opt/solr-10.0.0/modules/sql/lib/httpcore5-5.2.3.jar","manifestName":"","pomArtifactID":"httpcore5","archiveDigests":[{"value":"687cede1a44f70c7741abfab6ee2aa53dd2bfb54","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/sql/lib/httpcore5-5.2.3.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/sql/lib/httpcore5-5.2.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hf6x-8p5f-cgmf","versionConstraint":"<5.4.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.core5:httpcore5","version":"5.2.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hf6x-8p5f-cgmf","fix":{"state":"fixed","versions":["5.4.3"],"available":[{"date":"2026-08-13","kind":"first-observed","version":"5.4.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54399","https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4","https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e","https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hf6x-8p5f-cgmf","description":"Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-54399","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"urls":["https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54399","description":"Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length"}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4601","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4601","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"risk":0.6255000000000001,"urls":["https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/752180","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-25679","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"urls":["https://go.dev/cl/752180","https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4601","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10133","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10169","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:10701","https://access.redhat.com/errata/RHSA-2026:10712","https://access.redhat.com/errata/RHSA-2026:10929","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11375","https://access.redhat.com/errata/RHSA-2026:11412","https://access.redhat.com/errata/RHSA-2026:11413","https://access.redhat.com/errata/RHSA-2026:11686","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:11800","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13642","https://access.redhat.com/errata/RHSA-2026:13643","https://access.redhat.com/errata/RHSA-2026:13671","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19022","https://access.redhat.com/errata/RHSA-2026:19026","https://access.redhat.com/errata/RHSA-2026:19027","https://access.redhat.com/errata/RHSA-2026:19031","https://access.redhat.com/errata/RHSA-2026:19032","https://access.redhat.com/errata/RHSA-2026:19049","https://access.redhat.com/errata/RHSA-2026:19055","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19128","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19181","https://access.redhat.com/errata/RHSA-2026:19184","https://access.redhat.com/errata/RHSA-2026:19185","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19475","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20581","https://access.redhat.com/errata/RHSA-2026:20582","https://access.redhat.com/errata/RHSA-2026:20584","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22733","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24386","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:25043","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26445","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52389","https://access.redhat.com/errata/RHSA-2026:52390","https://access.redhat.com/errata/RHSA-2026:52391","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:5941","https://access.redhat.com/errata/RHSA-2026:5942","https://access.redhat.com/errata/RHSA-2026:5943","https://access.redhat.com/errata/RHSA-2026:5944","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:6341","https://access.redhat.com/errata/RHSA-2026:6344","https://access.redhat.com/errata/RHSA-2026:6382","https://access.redhat.com/errata/RHSA-2026:6383","https://access.redhat.com/errata/RHSA-2026:6388","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:6720","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:6949","https://access.redhat.com/errata/RHSA-2026:7005","https://access.redhat.com/errata/RHSA-2026:7009","https://access.redhat.com/errata/RHSA-2026:7011","https://access.redhat.com/errata/RHSA-2026:7259","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7315","https://access.redhat.com/errata/RHSA-2026:7328","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7665","https://access.redhat.com/errata/RHSA-2026:7669","https://access.redhat.com/errata/RHSA-2026:7674","https://access.redhat.com/errata/RHSA-2026:7833","https://access.redhat.com/errata/RHSA-2026:7834","https://access.redhat.com/errata/RHSA-2026:7876","https://access.redhat.com/errata/RHSA-2026:7877","https://access.redhat.com/errata/RHSA-2026:7878","https://access.redhat.com/errata/RHSA-2026:7879","https://access.redhat.com/errata/RHSA-2026:7883","https://access.redhat.com/errata/RHSA-2026:7992","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8314","https://access.redhat.com/errata/RHSA-2026:8322","https://access.redhat.com/errata/RHSA-2026:8324","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8434","https://access.redhat.com/errata/RHSA-2026:8456","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:8840","https://access.redhat.com/errata/RHSA-2026:8841","https://access.redhat.com/errata/RHSA-2026:8842","https://access.redhat.com/errata/RHSA-2026:8845","https://access.redhat.com/errata/RHSA-2026:8847","https://access.redhat.com/errata/RHSA-2026:8848","https://access.redhat.com/errata/RHSA-2026:8849","https://access.redhat.com/errata/RHSA-2026:8851","https://access.redhat.com/errata/RHSA-2026:8852","https://access.redhat.com/errata/RHSA-2026:8853","https://access.redhat.com/errata/RHSA-2026:8855","https://access.redhat.com/errata/RHSA-2026:8856","https://access.redhat.com/errata/RHSA-2026:8860","https://access.redhat.com/errata/RHSA-2026:8877","https://access.redhat.com/errata/RHSA-2026:8878","https://access.redhat.com/errata/RHSA-2026:8879","https://access.redhat.com/errata/RHSA-2026:8881","https://access.redhat.com/errata/RHSA-2026:8882","https://access.redhat.com/errata/RHSA-2026:8930","https://access.redhat.com/errata/RHSA-2026:8931","https://access.redhat.com/errata/RHSA-2026:8949","https://access.redhat.com/errata/RHSA-2026:9043","https://access.redhat.com/errata/RHSA-2026:9044","https://access.redhat.com/errata/RHSA-2026:9052","https://access.redhat.com/errata/RHSA-2026:9090","https://access.redhat.com/errata/RHSA-2026:9093","https://access.redhat.com/errata/RHSA-2026:9094","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9434","https://access.redhat.com/errata/RHSA-2026:9435","https://access.redhat.com/errata/RHSA-2026:9436","https://access.redhat.com/errata/RHSA-2026:9439","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9461","https://access.redhat.com/errata/RHSA-2026:9695","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-25679","https://bugzilla.redhat.com/show_bug.cgi?id=2445356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25679","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4981","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4981","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"risk":0.60975,"urls":["https://go.dev/cl/767860","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78803","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-33811","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"urls":["https://go.dev/cl/767860","https://go.dev/issue/78803","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4981","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:35995","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36617","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36776","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:39266","https://access.redhat.com/errata/RHSA-2026:39272","https://access.redhat.com/errata/RHSA-2026:39319","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54556","https://access.redhat.com/errata/RHSA-2026:54584","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56790","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60302","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61313","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/security/cve/CVE-2026-33811","https://bugzilla.redhat.com/show_bug.cgi?id=2467822","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4977","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4977","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"risk":0.5984999999999999,"urls":["https://go.dev/cl/771520","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78987","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."},"relatedVulnerabilities":[{"id":"CVE-2026-42499","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"urls":["https://go.dev/cl/771520","https://go.dev/issue/78987","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4977","https://access.redhat.com/errata/RHSA-2026:17713","https://access.redhat.com/errata/RHSA-2026:17714","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:63163","https://access.redhat.com/errata/RHSA-2026:63332","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:64818","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67148","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-42499","https://bugzilla.redhat.com/show_bug.cgi?id=2467809","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42499","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4986","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4986","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"risk":0.588,"urls":["https://go.dev/cl/759940","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78566","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-39820","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"urls":["https://go.dev/cl/759940","https://go.dev/issue/78566","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4986","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54883","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57401","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-39820","https://bugzilla.redhat.com/show_bug.cgi?id=2467820","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vqf4-7m7x-wgfc","versionConstraint":"<1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vqf4-7m7x-wgfc","fix":{"state":"fixed","versions":["1.8.1"],"available":[{"date":"2025-12-04","kind":"first-observed","version":"1.8.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12183","cwe":"CWE-125","type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11"}],"epss":[{"cve":"CVE-2025-12183","date":"2026-10-08","epss":0.00697,"percentile":0.51565}],"risk":0.5680550000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-12183","https://github.com/yawkat/lz4-java/releases/tag/v1.8.1","https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-12183","https://www.sonatype.com/security-advisories/cve-2025-12183","http://www.openwall.com/lists/oss-security/2025/12/01/5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vqf4-7m7x-wgfc","description":"LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS"},"relatedVulnerabilities":[{"id":"CVE-2025-12183","cvss":[{"type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12183","cwe":"CWE-125","type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11"}],"epss":[{"cve":"CVE-2025-12183","date":"2026-10-08","epss":0.00697,"percentile":0.51565}],"urls":["https://github.com/yawkat/lz4-java/releases/tag/v1.8.1","https://www.sonatype.com/security-advisories/cve-2025-12183","http://www.openwall.com/lists/oss-security/2025/12/01/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12183","description":"Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-31879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2021-31879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"risk":0.5519999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-31879"},"relatedVulnerabilities":[{"id":"CVE-2021-31879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"urls":["https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html","https://security.netapp.com/advisory/ntap-20210618-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2824","versionConstraint":">=1.22.0-0,<1.22.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2824","fix":{"state":"fixed","versions":["1.22.3"],"available":[{"date":"2024-05-07","kind":"release","version":"1.22.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24788","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-24788","date":"2026-10-08","epss":0.01001,"percentile":0.61733}],"risk":0.5455450000000001,"urls":["https://go.dev/cl/578375","https://groups.google.com/g/golang-announce/c/wkkO4P9stm0"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/66754","description":"A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop."},"relatedVulnerabilities":[{"id":"CVE-2024-24788","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24788","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-24788","date":"2026-10-08","epss":0.01001,"percentile":0.61733}],"urls":["http://www.openwall.com/lists/oss-security/2024/05/08/3","https://go.dev/cl/578375","https://go.dev/issue/66754","https://groups.google.com/g/golang-announce/c/wkkO4P9stm0","https://pkg.go.dev/vuln/GO-2024-2824","https://security.netapp.com/advisory/ntap-20240605-0002/","https://security.netapp.com/advisory/ntap-20240614-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24788","description":"A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"ff094141cd4f78fc","cpes":["cpe:2.3:a:apache:log4j-1.2-api:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_1.2_api:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:logging:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:api:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:1:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:2:2.25.3:*:*:*:*:*:*:*"],"name":"log4j-1.2-api","purl":"pkg:maven/org.apache.logging.log4j/log4j-1.2-api@2.25.3","type":"java-archive","version":"2.25.3","language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/solr-10.0.0/server/lib/ext/log4j-1.2-api-2.25.3.jar","manifestName":"","pomArtifactID":"log4j-1.2-api","archiveDigests":[{"value":"a7e550e638a5e534fd944616c5ae665a67e9501e","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/log4j-1.2-api-2.25.3.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/log4j-1.2-api-2.25.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h383-gmxw-35v2","versionConstraint":">=2.7,<2.25.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-1.2-api","version":"2.25.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-h383-gmxw-35v2","fix":{"state":"fixed","versions":["2.25.4"],"available":[{"date":"2026-04-14","kind":"first-observed","version":"2.25.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34479","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34479","date":"2026-10-08","epss":0.00909,"percentile":0.58735}],"risk":0.5408550000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34479","https://github.com/apache/logging-log4j2/pull/4078","https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5on","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html","https://logging.apache.org/security.html#CVE-2026-34479","http://www.openwall.com/lists/oss-security/2026/04/10/8"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h383-gmxw-35v2","description":"Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters"},"relatedVulnerabilities":[{"id":"CVE-2026-34479","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34479","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34479","date":"2026-10-08","epss":0.00909,"percentile":0.58735}],"urls":["https://github.com/apache/logging-log4j2/pull/4078","https://lists.apache.org/thread/gd0hp6mj17rn3kj279vgy4p7kd4zz5on","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html","https://logging.apache.org/security.html#CVE-2026-34479","http://www.openwall.com/lists/oss-security/2026/04/10/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34479","description":"The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such characters with a fatal error, which may cause downstream log processing systems to drop or fail to index affected records.\n\nTwo groups of users are affected:\n\n  *  Those using Log4j1XmlLayout directly in a Log4j Core 2 configuration file.\n  *  Those using the Log4j 1 configuration compatibility layer with org.apache.log4j.xml.XMLLayout specified as the layout class.\n\n\nUsers are advised to upgrade to Apache Log4j 1-to-Log4j 2 bridge version 2.25.4, which corrects this issue.\n\nNote: The Apache Log4j 1-to-Log4j 2 bridge is deprecated and will not be present in Log4j 3. Users are encouraged to consult the  Log4j 1 to Log4j 2 migration guide https://logging.apache.org/log4j/2.x/migrate-from-log4j1.html , and specifically the section on eliminating reliance on the bridge."}]},{"artifact":{"id":"1facc3e875c221a8","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"311ea62f27b26685b306dc24c4bbf765bc1950d9","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c653-97m9-rcg9","versionConstraint":">=4.2.0.Final,<4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c653-97m9-rcg9","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-16","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-50010","date":"2026-10-08","epss":0.00721,"percentile":0.52529}],"risk":0.54075,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://nvd.nist.gov/vuln/detail/CVE-2026-50010","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c653-97m9-rcg9","description":"Netty: Wrapping plain trust manager silently disables hostname verification"},"relatedVulnerabilities":[{"id":"CVE-2026-50010","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-50010","date":"2026-10-08","epss":0.00721,"percentile":0.52529}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-50010","https://bugzilla.redhat.com/show_bug.cgi?id=2488429","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50010","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-57rv-r2g8-2cj3","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-57rv-r2g8-2cj3","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42584","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42584","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42584","date":"2026-10-08","epss":0.00716,"percentile":0.52318}],"risk":0.52984,"urls":["https://github.com/netty/netty/security/advisories/GHSA-57rv-r2g8-2cj3","https://nvd.nist.gov/vuln/detail/CVE-2026-42584"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-57rv-r2g8-2cj3","description":"Netty has HttpClientCodec response desynchronization"},"relatedVulnerabilities":[{"id":"CVE-2026-42584","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42584","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42584","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42584","date":"2026-10-08","epss":0.00716,"percentile":0.52318}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-57rv-r2g8-2cj3","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-42584","https://bugzilla.redhat.com/show_bug.cgi?id=2477224","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42584.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42584","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"980dd54703beb52a","cpes":["cpe:2.3:a:apache:kafka-clients:3.9.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:kafka_clients:3.9.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:kafka:3.9.1:*:*:*:*:*:*:*"],"name":"kafka-clients","purl":"pkg:maven/org.apache.kafka/kafka-clients@3.9.1","type":"java-archive","version":"3.9.1","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.kafka","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/kafka-clients-3.9.1.jar","manifestName":"","pomArtifactID":"kafka-clients","archiveDigests":[{"value":"86ca079953ed5606257ff298c24666b26da6985b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/kafka-clients-3.9.1.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/kafka-clients-3.9.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.9.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5qcv-4rpc-jp93","versionConstraint":">=2.8.0,<3.9.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.kafka:kafka-clients","version":"3.9.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5qcv-4rpc-jp93","fix":{"state":"fixed","versions":["3.9.2"],"available":[{"date":"2026-04-14","kind":"first-observed","version":"3.9.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.7,"impactScore":5.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35554","cwe":"CWE-362","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-35554","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-35554","date":"2026-10-08","epss":0.00647,"percentile":0.49414}],"risk":0.52407,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-35554","https://issues.apache.org/jira/browse/KAFKA-19012","https://lists.apache.org/thread/f07x7j8ovyqhjd1to25jsnqbm6wj01d6","http://www.openwall.com/lists/oss-security/2026/04/07/6","https://github.com/apache/kafka/pull/21065","https://github.com/apache/kafka/pull/21285","https://github.com/apache/kafka/pull/21286","https://github.com/apache/kafka/pull/21287","https://github.com/apache/kafka/pull/21288","https://github.com/apache/kafka/commit/1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5qcv-4rpc-jp93","description":"Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-35554","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.7,"impactScore":5.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35554","cwe":"CWE-362","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-35554","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-35554","date":"2026-10-08","epss":0.00647,"percentile":0.49414}],"urls":["https://issues.apache.org/jira/browse/KAFKA-19012","https://lists.apache.org/thread/f07x7j8ovyqhjd1to25jsnqbm6wj01d6","http://www.openwall.com/lists/oss-security/2026/04/07/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35554","description":"A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics.\n\nWhen a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is prematurely deallocated and returned to the buffer pool. If a subsequent producer batch—potentially destined for a different topic—reuses this freed buffer before the original network request completes, the buffer contents may become corrupted. This can result in messages being delivered to unintended topics without any error being reported to the producer.\n\n\nData Confidentiality:\nMessages intended for one topic may be delivered to a different topic, potentially exposing sensitive data to consumers who have access to the destination topic but not the intended source topic.\n\nData Integrity:\nConsumers on the receiving topic may encounter unexpected or incompatible messages, leading to deserialization failures, processing errors, and corrupted downstream data.\n\nThis issue affects Apache Kafka versions ≤ 3.9.1, ≤ 4.0.1, and  ≤ 4.1.1.\n\nKafka users are advised to upgrade to 3.9.2, 4.0.2, 4.1.2, 4.2.0, or later to address this vulnerability."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.10.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pwqr-wmgm-9rr8","versionConstraint":">=4.2.0.Alpha1,<4.2.10.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-pwqr-wmgm-9rr8","fix":{"state":"fixed","versions":["4.2.10.Final"],"available":[{"date":"2026-03-27","kind":"first-observed","version":"4.2.10.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33870","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33870","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33870","date":"2026-10-08","epss":0.00698,"percentile":0.516}],"risk":0.5235,"urls":["https://github.com/netty/netty/security/advisories/GHSA-pwqr-wmgm-9rr8","https://w4ke.info/2025/06/18/funky-chunks.html","https://w4ke.info/2025/10/29/funky-chunks-2.html","https://www.rfc-editor.org/rfc/rfc9110","https://nvd.nist.gov/vuln/detail/CVE-2026-33870"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pwqr-wmgm-9rr8","description":"Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-33870","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33870","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33870","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33870","date":"2026-10-08","epss":0.00698,"percentile":0.516}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-pwqr-wmgm-9rr8","https://w4ke.info/2025/06/18/funky-chunks.html","https://w4ke.info/2025/10/29/funky-chunks-2.html","https://www.rfc-editor.org/rfc/rfc9110","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:17789","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:22619","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:7109","https://access.redhat.com/errata/RHSA-2026:7380","https://access.redhat.com/errata/RHSA-2026:8159","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-33870","https://bugzilla.redhat.com/show_bug.cgi?id=2452453","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33870.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33870","description":"Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue."}]},{"artifact":{"id":"7c13717a118443f2","cpes":["cpe:2.3:a:org.eclipse.jetty.security:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.security:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.security:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.security:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:security:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:security:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:security:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:security:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:security:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:12.0.27:*:*:*:*:*:*:*"],"name":"jetty-security","purl":"pkg:maven/org.eclipse.jetty/jetty-security@12.0.27","type":"java-archive","version":"12.0.27","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/opt/solr-10.0.0/server/lib/jetty-security-12.0.27.jar","manifestName":"","pomArtifactID":"jetty-security","archiveDigests":[{"value":"ac09a862d369681cf37dbd07d61c196bec0c8b20","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/jetty-security-12.0.27.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/jetty-security-12.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.36"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2fvj-hgj9-j2gr","versionConstraint":">=12.0.0,<=12.0.35 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-security","version":"12.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-2fvj-hgj9-j2gr","fix":{"state":"fixed","versions":["12.0.36"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"12.0.36"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10050","cwe":"CWE-173","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-10050","cwe":"CWE-303","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-10050","date":"2026-10-08","epss":0.00632,"percentile":0.48697}],"risk":0.51192,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://github.com/jetty/jetty.project/issues/15136","https://github.com/jetty/jetty.project/pull/15160","https://github.com/jetty/jetty.project/pull/15183","https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d","https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2fvj-hgj9-j2gr","description":"Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution"},"relatedVulnerabilities":[{"id":"CVE-2026-10050","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10050","cwe":"CWE-173","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-10050","cwe":"CWE-303","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-10050","date":"2026-10-08","epss":0.00632,"percentile":0.48697}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10050","description":"In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jppx-w49h-x2qq","versionConstraint":">=4.2.0.Final,<=4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jppx-w49h-x2qq","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"risk":0.5103,"urls":["https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq","https://nvd.nist.gov/vuln/detail/CVE-2026-56745","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jppx-w49h-x2qq","description":"Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-56745","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56745","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56745","date":"2026-10-08","epss":0.0063,"percentile":0.4857}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56745","description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"82bd49e59e12c322","cpes":["cpe:2.3:a:org.eclipse.jetty.server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:12.0.27:*:*:*:*:*:*:*"],"name":"jetty-server","purl":"pkg:maven/org.eclipse.jetty/jetty-server@12.0.27","type":"java-archive","version":"12.0.27","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","manifestName":"","pomArtifactID":"jetty-server","archiveDigests":[{"value":"65f40754e873638394ff06df7410f30967d15fdd","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.32"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xxh7-fcf3-rj7f","versionConstraint":">=12.0.0,<=12.0.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-server","version":"12.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xxh7-fcf3-rj7f","fix":{"state":"fixed","versions":["12.0.32"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"12.0.32"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1605","cwe":"CWE-400","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-1605","cwe":"CWE-401","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-1605","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-1605","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-1605","date":"2026-10-08","epss":0.00678,"percentile":0.50832}],"risk":0.5085,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-xxh7-fcf3-rj7f","https://nvd.nist.gov/vuln/detail/CVE-2026-1605","https://github.com/jetty/jetty.project/issues/14260","https://gitlab.eclipse.org/security/cve-assignment/-/issues/79"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xxh7-fcf3-rj7f","description":"The Eclipse Jetty Server Artifact has a Gzip request memory leak"},"relatedVulnerabilities":[{"id":"CVE-2026-1605","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1605","cwe":"CWE-400","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-1605","cwe":"CWE-401","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-1605","cwe":"CWE-401","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-1605","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-1605","date":"2026-10-08","epss":0.00678,"percentile":0.50832}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-xxh7-fcf3-rj7f","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25125","https://access.redhat.com/errata/RHSA-2026:25126","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-1605","https://bugzilla.redhat.com/show_bug.cgi?id=2444815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1605.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1605","description":"In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed.\n\n\nThis happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response.\nIn this case, since the response is not compressed, the release mechanism does not trigger, causing the leak."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6jqx-86gh-f27w","versionConstraint":">=4.2.0.Final,<=4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6jqx-86gh-f27w","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w","https://nvd.nist.gov/vuln/detail/CVE-2026-55831","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6jqx-86gh-f27w","description":"Netty SPDY SETTINGS frame count materializes unbounded settings map"},"relatedVulnerabilities":[{"id":"CVE-2026-55831","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55831","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-55831","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55831","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55831","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mvh2-crg5-v77c","versionConstraint":">=4.2.0.Final,<=4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mvh2-crg5-v77c","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c","https://nvd.nist.gov/vuln/detail/CVE-2026-55833","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mvh2-crg5-v77c","description":"Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation"},"relatedVulnerabilities":[{"id":"CVE-2026-55833","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55833","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-55833","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55833","description":"Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"bbc5cc41b592ab13","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"55b556602dd5ae7adf7a0ef4720195138018a623","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-93wv-jw9v-4972","versionConstraint":">=4.2.0,<=4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-93wv-jw9v-4972","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-08-01","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-56819","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56819","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"risk":0.49874999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972","https://nvd.nist.gov/vuln/detail/CVE-2026-56819","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-93wv-jw9v-4972","description":"Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-56819","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56819","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-56819","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56819","date":"2026-10-08","epss":0.00665,"percentile":0.50259}],"urls":["https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56819","description":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4009","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4009","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"risk":0.49575,"urls":["https://go.dev/cl/709858","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75676","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input.\n\nThis affects programs which parse untrusted PEM inputs."},"relatedVulnerabilities":[{"id":"CVE-2025-61723","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"urls":["https://go.dev/cl/709858","https://go.dev/issue/75676","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4009","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61723","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4006","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4006","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"risk":0.48525,"urls":["https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709860","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61725","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"urls":["https://go.dev/cl/709860","https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4006","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61725","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."}]},{"artifact":{"id":"02c5837caabe1018","cpes":["cpe:2.3:a:apache:log4j-layout-template-json:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_layout_template_json:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:json:2.25.3:*:*:*:*:*:*:*"],"name":"log4j-layout-template-json","purl":"pkg:maven/org.apache.logging.log4j/log4j-layout-template-json@2.25.3","type":"java-archive","version":"2.25.3","language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/solr-10.0.0/server/lib/ext/log4j-layout-template-json-2.25.3.jar","manifestName":"","pomArtifactID":"log4j-layout-template-json","archiveDigests":[{"value":"23ed918fa6e76480896db0e4d11cdda801ff2686","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/log4j-layout-template-json-2.25.3.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/log4j-layout-template-json-2.25.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w35j-pv5h-q9q9","versionConstraint":">=2.14.0,<2.25.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-layout-template-json","version":"2.25.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-w35j-pv5h-q9q9","fix":{"state":"fixed","versions":["2.25.4"],"available":[{"date":"2026-04-11","kind":"first-observed","version":"2.25.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34481","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34481","date":"2026-10-08","epss":0.00854,"percentile":0.57061}],"risk":0.48251,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34481","https://github.com/apache/logging-log4j2/pull/4080","https://lists.apache.org/thread/n34zdv00gbkdbzt2rx9rf5mqz6lhopcv","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html","https://logging.apache.org/security.html#CVE-2026-34481","http://www.openwall.com/lists/oss-security/2026/04/10/10"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w35j-pv5h-q9q9","description":"Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout"},"relatedVulnerabilities":[{"id":"CVE-2026-34481","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34481","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-34481","date":"2026-10-08","epss":0.00854,"percentile":0.57061}],"urls":["https://github.com/apache/logging-log4j2/pull/4080","https://lists.apache.org/thread/n34zdv00gbkdbzt2rx9rf5mqz6lhopcv","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html","https://logging.apache.org/security.html#CVE-2026-34481","http://www.openwall.com/lists/oss-security/2026/04/10/10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34481","description":"Apache Log4j's  JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records.\n\nAn attacker can exploit this issue only if both of the following conditions are met:\n\n  *  The application uses JsonTemplateLayout.\n  *  The application logs a MapMessage, or logs an object directly (e.g., via Logger.info(Object), which wraps it in an ObjectMessage), where the message contains an attacker-controlled floating-point value.\n\n\nUsers are advised to upgrade to Apache Log4j JSON Template Layout 2.25.4, which corrects this issue.\n\nNote: The fix released in version 2.25.4 did not cover all affected code paths. CVE-2026-49844 was assigned to the remaining issue, which concerns the MapMessage.asJson() serialization in Apache Log4j API and is fixed in versions 2.25.5 and 2.26.1."}]},{"artifact":{"id":"56d5f316ec5e4544","cpes":["cpe:2.3:a:apache:zookeeper:3.9.4:*:*:*:*:*:*:*"],"name":"zookeeper","purl":"pkg:maven/org.apache.zookeeper/zookeeper@3.9.4","type":"java-archive","version":"3.9.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.zookeeper","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/zookeeper-3.9.4.jar","manifestName":"","pomArtifactID":"zookeeper","archiveDigests":[{"value":"5ab49d76fcac9a33c255b0585bc1fc92e24166db","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/zookeeper-3.9.4.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/zookeeper-3.9.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.9.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7xrh-hqfc-g7qr","versionConstraint":">=3.9.0,<3.9.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.zookeeper:zookeeper","version":"3.9.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7xrh-hqfc-g7qr","fix":{"state":"fixed","versions":["3.9.5"],"available":[{"date":"2026-03-11","kind":"first-observed","version":"3.9.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-350","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24281","date":"2026-10-08","epss":0.00645,"percentile":0.49317}],"risk":0.480525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-24281","https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2","https://github.com/apache/zookeeper/commit/66c4efecdda1302d9cfb3af9eedb122b74452bf3","https://issues.apache.org/jira/browse/ZOOKEEPER-4986","http://www.openwall.com/lists/oss-security/2026/03/07/4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7xrh-hqfc-g7qr","description":"Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager"},"relatedVulnerabilities":[{"id":"CVE-2026-24281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-350","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24281","date":"2026-10-08","epss":0.00645,"percentile":0.49317}],"urls":["https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2","http://www.openwall.com/lists/oss-security/2026/03/07/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-24281","https://bugzilla.redhat.com/show_bug.cgi?id=2445449","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24281.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24281","description":"Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cmp6-m4wj-q63q","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cmp6-m4wj-q63q","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66566","cwe":"CWE-201","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66566","date":"2026-10-08","epss":0.00605,"percentile":0.47338}],"risk":0.47492499999999993,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-cmp6-m4wj-q63q","https://nvd.nist.gov/vuln/detail/CVE-2025-66566","https://github.com/yawkat/lz4-java/commit/33d180cb70c4d93c80fb0dc3ab3002f457e93840"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cmp6-m4wj-q63q","description":"yawkat LZ4 Java has a possible information leak in Java safe decompressor"},"relatedVulnerabilities":[{"id":"CVE-2025-66566","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66566","cwe":"CWE-201","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66566","date":"2026-10-08","epss":0.00605,"percentile":0.47338}],"urls":["https://github.com/yawkat/lz4-java/commit/33d180cb70c4d93c80fb0dc3ab3002f457e93840","https://github.com/yawkat/lz4-java/security/advisories/GHSA-cmp6-m4wj-q63q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66566","description":"yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4870","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4870","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"risk":0.46575,"urls":["https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763767","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.\n\nThis only affects TLS 1.3."},"relatedVulnerabilities":[{"id":"CVE-2026-32283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"urls":["https://go.dev/cl/763767","https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4870","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11704","https://access.redhat.com/errata/RHSA-2026:11711","https://access.redhat.com/errata/RHSA-2026:11712","https://access.redhat.com/errata/RHSA-2026:11863","https://access.redhat.com/errata/RHSA-2026:11881","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17075","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19134","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19136","https://access.redhat.com/errata/RHSA-2026:19137","https://access.redhat.com/errata/RHSA-2026:19139","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19156","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19351","https://access.redhat.com/errata/RHSA-2026:19352","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19369","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55898","https://access.redhat.com/errata/RHSA-2026:55900","https://access.redhat.com/errata/RHSA-2026:55901","https://access.redhat.com/errata/RHSA-2026:55902","https://access.redhat.com/errata/RHSA-2026:55903","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:57802","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65343","https://access.redhat.com/errata/RHSA-2026:65514","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66084","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:66523","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/security/cve/CVE-2026-32283","https://bugzilla.redhat.com/show_bug.cgi?id=2456338","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32283","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4971","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4971","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"risk":0.46499999999999997,"urls":["https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://go.dev/cl/775320"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79006","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."},"relatedVulnerabilities":[{"id":"CVE-2026-39836","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"urls":["https://go.dev/cl/775320","https://go.dev/issue/79006","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4971"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4947","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4947","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"risk":0.46125000000000005,"urls":["https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758320","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},"relatedVulnerabilities":[{"id":"CVE-2026-32280","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"urls":["https://go.dev/cl/758320","https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4947","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16476","https://access.redhat.com/errata/RHSA-2026:16477","https://access.redhat.com/errata/RHSA-2026:16505","https://access.redhat.com/errata/RHSA-2026:16508","https://access.redhat.com/errata/RHSA-2026:16532","https://access.redhat.com/errata/RHSA-2026:16534","https://access.redhat.com/errata/RHSA-2026:16535","https://access.redhat.com/errata/RHSA-2026:16537","https://access.redhat.com/errata/RHSA-2026:16542","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21338","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:22130","https://access.redhat.com/errata/RHSA-2026:22141","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22268","https://access.redhat.com/errata/RHSA-2026:22309","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22415","https://access.redhat.com/errata/RHSA-2026:22422","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22958","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22960","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:22962","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23244","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24359","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24478","https://access.redhat.com/errata/RHSA-2026:24716","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:28196","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:39894","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49526","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49838","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:59834","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61685","https://access.redhat.com/errata/RHSA-2026:61906","https://access.redhat.com/errata/RHSA-2026:61907","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/security/cve/CVE-2026-32280","https://bugzilla.redhat.com/show_bug.cgi?id=2456339","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32280","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."}]},{"artifact":{"id":"802cfdfe88595c79","cpes":["cpe:2.3:a:apache:log4j-api:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:api:2.25.3:*:*:*:*:*:*:*"],"name":"log4j-api","purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.25.3","type":"java-archive","version":"2.25.3","language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/solr-10.0.0/server/lib/ext/log4j-api-2.25.3.jar","manifestName":"","pomArtifactID":"log4j-api","archiveDigests":[{"value":"fb385330d89c2d61058ef649403f214633569205","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/log4j-api-2.25.3.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/log4j-api-2.25.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.13.1,<2.25.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.25.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qv9r-c865-cp47","fix":{"state":"fixed","versions":["2.25.5"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"2.25.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"risk":0.459345,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization"},"relatedVulnerabilities":[{"id":"CVE-2026-49844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values."}]},{"artifact":{"id":"980dd54703beb52a","cpes":["cpe:2.3:a:apache:kafka-clients:3.9.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:kafka_clients:3.9.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:kafka:3.9.1:*:*:*:*:*:*:*"],"name":"kafka-clients","purl":"pkg:maven/org.apache.kafka/kafka-clients@3.9.1","type":"java-archive","version":"3.9.1","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.kafka","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/kafka-clients-3.9.1.jar","manifestName":"","pomArtifactID":"kafka-clients","archiveDigests":[{"value":"86ca079953ed5606257ff298c24666b26da6985b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/kafka-clients-3.9.1.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/kafka-clients-3.9.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.9.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wf66-mphr-4c4r","versionConstraint":">=0.11.0,<3.9.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.kafka:kafka-clients","version":"3.9.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wf66-mphr-4c4r","fix":{"state":"fixed","versions":["3.9.2"],"available":[{"date":"2026-04-25","kind":"first-observed","version":"3.9.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33558","cwe":"CWE-533","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-33558","date":"2026-10-08","epss":0.00889,"percentile":0.58104}],"risk":0.457835,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-33558","https://kafka.apache.org/cve-list","https://lists.apache.org/thread/pz5g4ky3h0k91tfd14p0dzqjp80960kl","http://www.openwall.com/lists/oss-security/2026/04/17/3"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wf66-mphr-4c4r","description":"Apache Kafka exposes sensitive information in its DEBUG logs"},"relatedVulnerabilities":[{"id":"CVE-2026-33558","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33558","cwe":"CWE-533","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-33558","date":"2026-10-08","epss":0.00889,"percentile":0.58104}],"urls":["https://kafka.apache.org/cve-list","https://lists.apache.org/thread/pz5g4ky3h0k91tfd14p0dzqjp80960kl","http://www.openwall.com/lists/oss-security/2026/04/17/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33558","description":"Information exposure vulnerability has been identified in Apache Kafka.\n\nThe NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are:\n\n\n  *  AlterConfigsRequest\n\n  *  AlterUserScramCredentialsRequest\n\n  *  ExpireDelegationTokenRequest\n\n  *  IncrementalAlterConfigsRequest\n\n  *  RenewDelegationTokenRequest\n\n  *  SaslAuthenticateRequest\n\n  *  createDelegationTokenResponse\n\n  *  describeDelegationTokenResponse\n\n  *  SaslAuthenticateResponse\n\n\nThis issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability."}]},{"artifact":{"id":"bbc5cc41b592ab13","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"55b556602dd5ae7adf7a0ef4720195138018a623","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c2gf-v879-257j","versionConstraint":">=4.2.0.Alpha1,<=4.2.14.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c2gf-v879-257j","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48043","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48043","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48043","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48043","date":"2026-10-08","epss":0.00882,"percentile":0.57908}],"risk":0.45423,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","https://nvd.nist.gov/vuln/detail/CVE-2026-48043","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/security/cve/CVE-2026-48043","https://bugzilla.redhat.com/show_bug.cgi?id=2488442","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:53645","https://github.com/netty/netty/commit/db6138b168699736a6463c367e12ad0a4c36a25e","https://github.com/netty/netty/commit/3d45a1e4e8eb99144f716e54be5ac57e525fa7ca"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c2gf-v879-257j","description":"netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-48043","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48043","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48043","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-48043","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48043","date":"2026-10-08","epss":0.00882,"percentile":0.57908}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/security/cve/CVE-2026-48043","https://bugzilla.redhat.com/show_bug.cgi?id=2488442","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48043","description":"Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"55f6f9e02f0d59e8","cpes":["cpe:2.3:a:io.netty.transport-classes-epoll:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.transport-classes-epoll:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes-epoll:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes-epoll:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes_epoll:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes_epoll:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.transport-classes-epoll:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.transport-classes-epoll:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes-epoll:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes-epoll:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes_epoll:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes_epoll:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes-epoll:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes-epoll:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes_epoll:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes_epoll:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-classes:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_classes:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes-epoll:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes-epoll:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes_epoll:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes_epoll:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-classes:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_classes:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:transport-classes-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:transport_classes_epoll:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-transport-classes-epoll","purl":"pkg:maven/io.netty/netty-transport-classes-epoll@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-transport-classes-epoll-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-transport-classes-epoll","archiveDigests":[{"value":"b61968c0cb9c474df7a0ddc7cd577fed677efbbb","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-transport-classes-epoll-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-transport-classes-epoll-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rwm7-x88c-3g2p","versionConstraint":">=4.2.0.Final,<4.2.13.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-transport-classes-epoll","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rwm7-x88c-3g2p","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-07-25","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42577","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42577","date":"2026-10-08","epss":0.00583,"percentile":0.46186}],"risk":0.43724999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-rwm7-x88c-3g2p","https://github.com/netty/netty/pull/16689","https://github.com/netty/netty/commit/0ec3d97fab376e243d328ac95fbd288ba0f6e22d","https://nvd.nist.gov/vuln/detail/CVE-2026-42577"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rwm7-x88c-3g2p","description":"Netty epoll transport denial of service via RST on half-closed TCP connection"},"relatedVulnerabilities":[{"id":"CVE-2026-42577","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42577","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42577","date":"2026-10-08","epss":0.00583,"percentile":0.46186}],"urls":["https://github.com/netty/netty/commit/0ec3d97fab376e243d328ac95fbd288ba0f6e22d","https://github.com/netty/netty/pull/16689","https://github.com/netty/netty/security/advisories/GHSA-rwm7-x88c-3g2p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42577","description":"Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread. This vulnerability is fixed in 4.2.13.Final."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4342","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4342","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"risk":0.430675,"urls":["https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736713","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."},"relatedVulnerabilities":[{"id":"CVE-2025-61728","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"urls":["https://go.dev/cl/736713","https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4342","http://www.openwall.com/lists/oss-security/2026/01/15/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61728","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"f7d0cee212fdb1ad","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"3c97f7fad069f7cfae639d790bd93d6a0b2dff31","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"bcabfae824c86510","cpes":["cpe:2.3:a:apache:calcite-core:1.37.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:calcite_core:1.37.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:calcite:1.37.0:*:*:*:*:*:*:*"],"name":"calcite-core","purl":"pkg:maven/org.apache.calcite/calcite-core@1.37.0","type":"java-archive","version":"1.37.0","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.calcite","virtualPath":"/opt/solr-10.0.0/modules/sql/lib/calcite-core-1.37.0.jar","manifestName":"","pomArtifactID":"calcite-core","archiveDigests":[{"value":"537a3281dfefbd7939d27785732a2aafddd3abcb","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/sql/lib/calcite-core-1.37.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/sql/lib/calcite-core-1.37.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.42.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c2rv-hwqm-wjpg","versionConstraint":">=1.5.0,<1.42.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.calcite:calcite-core","version":"1.37.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c2rv-hwqm-wjpg","fix":{"state":"fixed","versions":["1.42.0"],"available":[{"date":"2026-07-10","kind":"first-observed","version":"1.42.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46718","cwe":"CWE-470","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46718","date":"2026-10-08","epss":0.00688,"percentile":0.51223}],"risk":0.39559999999999995,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-46718","https://lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v","http://www.openwall.com/lists/oss-security/2026/06/01/7","https://github.com/apache/calcite/commit/5855cfa14d8038e2a123ff6ce9722edce0e0cc25","https://issues.apache.org/jira/browse/CALCITE-7532"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c2rv-hwqm-wjpg","description":"Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes"},"relatedVulnerabilities":[{"id":"CVE-2026-46718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46718","cwe":"CWE-470","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46718","date":"2026-10-08","epss":0.00688,"percentile":0.51223}],"urls":["https://lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v","http://www.openwall.com/lists/oss-security/2026/06/01/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46718","description":"Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite.\n\nThis issue affects Apache Calcite: from 1.5.0 before 1.42.\n\nUsers are recommended to upgrade to version 1.42, which fixes the issue."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3751","versionConstraint":"<1.23.10||>=1.24.0-0,<1.24.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3751","fix":{"state":"fixed","versions":["1.23.10","1.24.4"],"available":[{"date":"2025-06-05","kind":"release","version":"1.23.10"},{"date":"2025-06-05","kind":"release","version":"1.24.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-4673","date":"2026-10-08","epss":0.00666,"percentile":0.50281}],"risk":0.39293999999999996,"urls":["https://go.dev/issue/73816","https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/679257","description":"Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2025-4673","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-4673","date":"2026-10-08","epss":0.00666,"percentile":0.50281}],"urls":["https://go.dev/cl/679257","https://go.dev/issue/73816","https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A","https://pkg.go.dev/vuln/GO-2025-3751"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4673","description":"Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-3105","versionConstraint":"<1.22.7||>=1.23.0-0,<1.23.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-3105","fix":{"state":"fixed","versions":["1.22.7","1.23.1"],"available":[{"date":"2024-09-05","kind":"release","version":"1.22.7"},{"date":"2024-09-05","kind":"release","version":"1.23.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34155","date":"2026-10-08","epss":0.00839,"percentile":0.56543}],"risk":0.39013499999999995,"urls":["https://go.dev/issue/69138","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/611238","description":"Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2024-34155","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34155","date":"2026-10-08","epss":0.00839,"percentile":0.56543}],"urls":["https://go.dev/cl/611238","https://go.dev/issue/69138","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk","https://pkg.go.dev/vuln/GO-2024-3105","https://security.netapp.com/advisory/ntap-20240926-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34155","description":"Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"f7d0cee212fdb1ad","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"3c97f7fad069f7cfae639d790bd93d6a0b2dff31","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"f56575528ea62359","cpes":["cpe:2.3:a:io.netty.codec-compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_compression:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-compression","purl":"pkg:maven/io.netty/netty-codec-compression@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-compression-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-compression","archiveDigests":[{"value":"fadf334ce949ae99b96b4b9d95d59c30a5dc2614","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-compression-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-compression-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-558v-64gr-wgg4","versionConstraint":">=4.2.0.Final,<4.2.16.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-compression","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-558v-64gr-wgg4","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"risk":0.3726,"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-558v-64gr-wgg4","description":"Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang"},"relatedVulnerabilities":[{"id":"CVE-2026-59901","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3420","versionConstraint":"<1.22.11||>=1.23.0-0,<1.23.5||>=1.24.0-0,<1.24.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3420","fix":{"state":"fixed","versions":["1.22.11","1.23.5","1.24.0-rc.2"],"available":[{"date":"2025-01-16","kind":"release","version":"1.22.11"},{"date":"2025-01-16","kind":"release","version":"1.23.5"},{"date":"2025-01-16","kind":"release","version":"1.24.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45336","date":"2026-10-08","epss":0.00671,"percentile":0.50497}],"risk":0.372405,"urls":["https://go.dev/issue/70530","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/643100","description":"The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com.\n\nIn the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2."},"relatedVulnerabilities":[{"id":"CVE-2024-45336","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45336","date":"2026-10-08","epss":0.00671,"percentile":0.50497}],"urls":["https://go.dev/cl/643100","https://go.dev/issue/70530","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ","https://pkg.go.dev/vuln/GO-2025-3420","https://security.netapp.com/advisory/ntap-20250221-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-45336","description":"The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xxqh-mfjm-7mv9","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xxqh-mfjm-7mv9","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":5.8,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42581","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42581","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42581","date":"2026-10-08","epss":0.00684,"percentile":0.51071}],"risk":0.36936,"urls":["https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9","https://nvd.nist.gov/vuln/detail/CVE-2026-42581"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xxqh-mfjm-7mv9","description":"Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization"},"relatedVulnerabilities":[{"id":"CVE-2026-42581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":5.8,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42581","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42581","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42581","date":"2026-10-08","epss":0.00684,"percentile":0.51071}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-42581","https://bugzilla.redhat.com/show_bug.cgi?id=2477232","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42581.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42581","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"f7d0cee212fdb1ad","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"3c97f7fad069f7cfae639d790bd93d6a0b2dff31","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"f56575528ea62359","cpes":["cpe:2.3:a:io.netty.codec-compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_compression:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-compression:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_compression:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-compression","purl":"pkg:maven/io.netty/netty-codec-compression@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-compression-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-compression","archiveDigests":[{"value":"fadf334ce949ae99b96b4b9d95d59c30a5dc2614","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-compression-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-compression-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mj4r-2hfc-f8p6","versionConstraint":"<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-compression","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mj4r-2hfc-f8p6","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42583","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42583","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42583","date":"2026-10-08","epss":0.00486,"percentile":0.39915}],"risk":0.3645,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mj4r-2hfc-f8p6","https://nvd.nist.gov/vuln/detail/CVE-2026-42583"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mj4r-2hfc-f8p6","description":"Netty Lz4FrameDecoder is vulnerable to resource exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-42583","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42583","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42583","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42583","date":"2026-10-08","epss":0.00486,"percentile":0.39915}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-mj4r-2hfc-f8p6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42583","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4f6-jm68-57ww","versionConstraint":">=4.2.0.Final,<=4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4f6-jm68-57ww","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"risk":0.362355,"urls":["https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4f6-jm68-57ww","description":"Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service"},"relatedVulnerabilities":[{"id":"CVE-2026-59899","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59899","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59899","date":"2026-10-08","epss":0.00609,"percentile":0.47536}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59899","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4155","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4155","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"risk":0.34275,"urls":["https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/725920","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"urls":["https://go.dev/cl/725920","https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4155"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61729","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."}]},{"artifact":{"id":"c8c16f22491b4c1b","cpes":["cpe:2.3:a:io.netty.handler-proxy:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler-proxy:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler-proxy:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler-proxy:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler_proxy:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler_proxy:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler-proxy:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler-proxy:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler-proxy:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler-proxy:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler_proxy:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler_proxy:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler-proxy:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler-proxy:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler_proxy:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler_proxy:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler-proxy:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler-proxy:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler_proxy:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler_proxy:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler-proxy:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler_proxy:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-handler-proxy","purl":"pkg:maven/io.netty/netty-handler-proxy@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-handler-proxy-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-handler-proxy","archiveDigests":[{"value":"1f0f9fb2f321cc697f13d802cf80c37889ce421a","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-handler-proxy-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-handler-proxy-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-45q3-82m4-75jr","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler-proxy","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-45q3-82m4-75jr","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42578","cwe":"CWE-113","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42578","cwe":"CWE-93","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42578","date":"2026-10-08","epss":0.01153,"percentile":0.66002}],"risk":0.340135,"urls":["https://github.com/netty/netty/security/advisories/GHSA-45q3-82m4-75jr","https://github.com/advisories/GHSA-84h7-rjj3-6jx4","https://nvd.nist.gov/vuln/detail/CVE-2026-42578"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-45q3-82m4-75jr","description":"Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)"},"relatedVulnerabilities":[{"id":"CVE-2026-42578","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42578","cwe":"CWE-113","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42578","cwe":"CWE-93","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42578","date":"2026-10-08","epss":0.01153,"percentile":0.66002}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-45q3-82m4-75jr","https://access.redhat.com/errata/RHSA-2026:23808","https://access.redhat.com/errata/RHSA-2026:24502","https://access.redhat.com/errata/RHSA-2026:25123","https://access.redhat.com/errata/RHSA-2026:28010","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-42578","https://bugzilla.redhat.com/show_bug.cgi?id=2477226","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42578.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42578","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-10524","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10524","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"risk":0.32130000000000003,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10524"},"relatedVulnerabilities":[{"id":"CVE-2024-10524","cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"urls":["https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778","https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/","https://seclists.org/oss-sec/2024/q4/107","http://www.openwall.com/lists/oss-security/2024/11/18/6","https://security.netapp.com/advisory/ntap-20250321-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3956","versionConstraint":"<1.23.12||>=1.24.0,<1.24.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3956","fix":{"state":"fixed","versions":["1.23.12","1.24.6"],"available":[{"date":"2025-08-06","kind":"release","version":"1.23.12"},{"date":"2025-08-06","kind":"release","version":"1.24.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47906","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47906","date":"2026-10-08","epss":0.0055,"percentile":0.44269}],"risk":0.31625,"urls":["https://go.dev/issue/74466","https://groups.google.com/g/golang-announce/c/x5MKroML2yM"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/691775","description":"If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (\"\", \".\", and \"..\"), can result in the binaries listed in the PATH being unexpectedly returned."},"relatedVulnerabilities":[{"id":"CVE-2025-47906","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47906","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47906","date":"2026-10-08","epss":0.0055,"percentile":0.44269}],"urls":["https://go.dev/cl/691775","https://go.dev/issue/74466","https://groups.google.com/g/golang-announce/c/x5MKroML2yM","https://pkg.go.dev/vuln/GO-2025-3956","http://www.openwall.com/lists/oss-security/2025/08/06/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47906","description":"If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (\"\", \".\", and \"..\"), can result in the binaries listed in the PATH being unexpectedly returned."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4007","versionConstraint":"<1.24.9||>=1.25.0,<1.25.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4007","fix":{"state":"fixed","versions":["1.24.9","1.25.3"],"available":[{"date":"2025-10-13","kind":"release","version":"1.24.9"},{"date":"2025-10-13","kind":"release","version":"1.25.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"risk":0.3045,"urls":["https://go.dev/cl/709854","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75681","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58187","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"urls":["https://go.dev/cl/709854","https://go.dev/issue/75681","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4007","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58187","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4012","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4012","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"risk":0.290975,"urls":["https://go.dev/cl/709855","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75672","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-58186","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"urls":["https://go.dev/cl/709855","https://go.dev/issue/75672","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4012","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58186","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."}]},{"artifact":{"id":"bbc5cc41b592ab13","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"55b556602dd5ae7adf7a0ef4720195138018a623","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-563q-j3cm-6jxm","versionConstraint":">=4.2.0.Final,<=4.2.14.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-563q-j3cm-6jxm","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-16","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50560","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-50560","date":"2026-10-08","epss":0.00524,"percentile":0.42611}],"risk":0.29081999999999997,"urls":["https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm","https://nvd.nist.gov/vuln/detail/CVE-2026-50560","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-563q-j3cm-6jxm","description":"Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature"},"relatedVulnerabilities":[{"id":"CVE-2026-50560","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50560","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-50560","date":"2026-10-08","epss":0.00524,"percentile":0.42611}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm","https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50560","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4011","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4011","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/cl/709856","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75671","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2025-58185","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709856","https://go.dev/issue/75671","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4011","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58185","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4015","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4015","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709859","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61724","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709859","https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4015","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61724","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4013","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4013","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"risk":0.28575,"urls":["https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709853","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58188","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"urls":["https://go.dev/cl/709853","https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4013","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58188","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"8ef1504da9b7bb58","cpes":["cpe:2.3:a:apache:log4j-core:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_core:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:core:2.25.3:*:*:*:*:*:*:*"],"name":"log4j-core","purl":"pkg:maven/org.apache.logging.log4j/log4j-core@2.25.3","type":"java-archive","version":"2.25.3","language":"java","licenses":["\"Apache-2.0\";link=\"https://www.apache.org/licenses/LICENSE-2.0.txt\""],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","manifestName":"","pomArtifactID":"log4j-core","archiveDigests":[{"value":"dd9c8ecba5c8dc5e1574804d0bfdc1ef155ad9ea","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/log4j-core-2.25.3.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6hg6-v5c8-fphq","versionConstraint":">=2.12.0,<2.25.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-core","version":"2.25.3"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6hg6-v5c8-fphq","fix":{"state":"fixed","versions":["2.25.4"],"available":[{"date":"2026-04-14","kind":"first-observed","version":"2.25.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-34477","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-34477","date":"2026-10-08","epss":0.00502,"percentile":0.41032}],"risk":0.28363,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-34477","https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6hg6-v5c8-fphq","description":"Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration"},"relatedVulnerabilities":[{"id":"CVE-2026-34477","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34477","cwe":"CWE-297","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-34477","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-34477","date":"2026-10-08","epss":0.00502,"percentile":0.41032}],"urls":["https://github.com/apache/logging-log4j2/pull/4075","https://lists.apache.org/thread/lkx8cl46t2bvkcwfcb2pd43ygc097lq4","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName","https://logging.apache.org/security.html#CVE-2026-34477"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34477","description":"The fix for  CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161  was incomplete: it addressed hostname verification only when enabled via the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property, but not when configured through the  verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName  attribute of the <Ssl> element.\n\nAlthough the verifyHostName configuration attribute was introduced in Log4j Core 2.12.0, it was silently ignored in all versions through 2.25.3, leaving TLS connections vulnerable to interception regardless of the configured value.\n\nA network-based attacker may be able to perform a man-in-the-middle attack when all of the following conditions are met:\n\n  *  An SMTP, Socket, or Syslog appender is in use.\n  *  TLS is configured via a nested <Ssl> element.\n  *  The attacker can present a certificate issued by a CA trusted by the appender's configured trust store, or by the default Java trust store if none is configured.\nThis issue does not affect users of the HTTP appender, which uses a separate  verifyHostname https://logging.apache.org/log4j/2.x/manual/appenders/network.html#HttpAppender-attr-verifyHostName  attribute that was not subject to this bug and verifies host names by default.\n\nUsers are advised to upgrade to Apache Log4j Core 2.25.4, which corrects this issue."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3849","versionConstraint":"<1.23.12||>=1.24.0,<1.24.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3849","fix":{"state":"fixed","versions":["1.23.12","1.24.6"],"available":[{"date":"2025-08-06","kind":"release","version":"1.23.12"},{"date":"2025-08-06","kind":"release","version":"1.24.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47907","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47907","date":"2026-10-08","epss":0.00383,"percentile":0.30221}],"risk":0.277675,"urls":["https://go.dev/issue/74831","https://groups.google.com/g/golang-announce/c/x5MKroML2yM"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/693735","description":"Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error."},"relatedVulnerabilities":[{"id":"CVE-2025-47907","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47907","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47907","date":"2026-10-08","epss":0.00383,"percentile":0.30221}],"urls":["https://go.dev/cl/693735","https://go.dev/issue/74831","https://groups.google.com/g/golang-announce/c/x5MKroML2yM","https://pkg.go.dev/vuln/GO-2025-3849","http://www.openwall.com/lists/oss-security/2025/08/06/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47907","description":"Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.2745,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77214"},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xx22-p4ch-683r","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xx22-p4ch-683r","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"risk":0.26795,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r","https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xx22-p4ch-683r","description":"LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-59949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"urls":["https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1","https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59949","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4946","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4946","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"risk":0.26625,"urls":["https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758061","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.\n\nThis only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},"relatedVulnerabilities":[{"id":"CVE-2026-32281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"urls":["https://go.dev/cl/758061","https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4946"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3373","versionConstraint":"<1.22.11||>=1.23.0-0,<1.23.5||>=1.24.0-0,<1.24.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3373","fix":{"state":"fixed","versions":["1.22.11","1.23.5","1.24.0-rc.2"],"available":[{"date":"2025-01-16","kind":"release","version":"1.22.11"},{"date":"2025-01-16","kind":"release","version":"1.23.5"},{"date":"2025-01-16","kind":"release","version":"1.24.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45341","date":"2026-10-08","epss":0.00476,"percentile":0.39127}],"risk":0.26417999999999997,"urls":["https://go.dev/issue/71156","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/643099","description":"A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain.\n\nCertificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs."},"relatedVulnerabilities":[{"id":"CVE-2024-45341","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45341","date":"2026-10-08","epss":0.00476,"percentile":0.39127}],"urls":["https://go.dev/cl/643099","https://go.dev/issue/71156","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ","https://pkg.go.dev/vuln/GO-2025-3373","https://security.netapp.com/advisory/ntap-20250221-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-45341","description":"A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs."}]},{"artifact":{"id":"bbc5cc41b592ab13","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"55b556602dd5ae7adf7a0ef4720195138018a623","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5x3r-wrvg-rp6q","versionConstraint":">=4.2.0.Final,<=4.2.14.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5x3r-wrvg-rp6q","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-09","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47244","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47244","date":"2026-10-08","epss":0.00507,"percentile":0.41331}],"risk":0.26110500000000003,"urls":["https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-47244"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q","description":"Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced"},"relatedVulnerabilities":[{"id":"CVE-2026-47244","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47244","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47244","date":"2026-10-08","epss":0.00507,"percentile":0.41331}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47244","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"1facc3e875c221a8","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"311ea62f27b26685b306dc24c4bbf765bc1950d9","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.17.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4c3-7fpv-j4q5","versionConstraint":">=4.2.0.Final,<=4.2.16.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4c3-7fpv-j4q5","fix":{"state":"fixed","versions":["4.2.17.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.2.17.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"risk":0.250685,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5","https://nvd.nist.gov/vuln/detail/CVE-2026-75595","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4c3-7fpv-j4q5","description":"Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext"},"relatedVulnerabilities":[{"id":"CVE-2026-75595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75595","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gcjf-9mgh-3p7g","versionConstraint":">=4.2.0.Final,<4.2.16.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gcjf-9mgh-3p7g","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"risk":0.248775,"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gcjf-9mgh-3p7g","description":"Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder"},"relatedVulnerabilities":[{"id":"CVE-2026-59921","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59921","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59921","date":"2026-10-08","epss":0.00465,"percentile":0.38296}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59921","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\\r\\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4mp9-239f-g9hg","versionConstraint":">=4.2.0.Final,<=4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4mp9-239f-g9hg","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"risk":0.24803499999999998,"urls":["https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4mp9-239f-g9hg","description":"Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation"},"relatedVulnerabilities":[{"id":"CVE-2026-59898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59898","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59898","date":"2026-10-08","epss":0.00439,"percentile":0.36145}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59898","description":"Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"risk":0.243225,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy"},"relatedVulnerabilities":[{"id":"CVE-2026-59888","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"f7d0cee212fdb1ad","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"3c97f7fad069f7cfae639d790bd93d6a0b2dff31","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-core-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.19.0,<2.21.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.21.1"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.21.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4008","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4008","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/707776","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."},"relatedVulnerabilities":[{"id":"CVE-2025-58189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/707776","https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4008","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58189","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4010","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4010","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/cl/709857","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75678","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."},"relatedVulnerabilities":[{"id":"CVE-2025-47912","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/709857","https://go.dev/issue/75678","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4010","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47912","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."}]},{"artifact":{"id":"4470e32e55cfd05d","cpes":["cpe:2.3:a:apache:httpclient5:5.2.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:client5:5.2.1:*:*:*:*:*:*:*"],"name":"httpclient5","purl":"pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.2.1","type":"java-archive","version":"5.2.1","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.httpcomponents.client5","virtualPath":"/opt/solr-10.0.0/modules/sql/lib/httpclient5-5.2.1.jar","manifestName":"","pomArtifactID":"httpclient5","archiveDigests":[{"value":"0c900514d3446d9ce5d9dbd90c21192048125440","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/sql/lib/httpclient5-5.2.1.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/sql/lib/httpclient5-5.2.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.6.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hjcp-jmpx-g3qm","versionConstraint":">=5.0-alpha1,<5.6.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.client5:httpclient5","version":"5.2.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hjcp-jmpx-g3qm","fix":{"state":"fixed","versions":["5.6.3"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"5.6.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-64607","date":"2026-10-08","epss":0.00464,"percentile":0.3822}],"risk":0.23896,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-64607","https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","https://github.com/apache/httpcomponents-client/commit/55733f4121f7ba26ddf04fe12739d9c15962cb94","https://github.com/apache/httpcomponents-client/commit/ebac9512f555c4a355cad3f59ef2db69b597cc97","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.6.3","https://github.com/apache/httpcomponents-client/releases/tag/rel/v5.7-alpha1","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hjcp-jmpx-g3qm","description":"Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-64607","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64607","cwe":"CWE-772","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-64607","date":"2026-10-08","epss":0.00464,"percentile":0.3822}],"urls":["https://lists.apache.org/thread/qqfzo3fqcdk4l5496vz95ppvl4ty511q","http://www.openwall.com/lists/oss-security/2026/08/13/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64607","description":"HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model.\n\nThis issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2."}]},{"artifact":{"id":"bbc5cc41b592ab13","cpes":["cpe:2.3:a:io.netty.codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http2:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http2:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http2:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http2","purl":"pkg:maven/io.netty/netty-codec-http2@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http2","archiveDigests":[{"value":"55b556602dd5ae7adf7a0ef4720195138018a623","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http2-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c69g-56f8-xwqj","versionConstraint":">=4.2.0.Final,<=4.2.15.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http2","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c69g-56f8-xwqj","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59900","date":"2026-10-08","epss":0.00398,"percentile":0.31911}],"risk":0.23680999999999996,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c69g-56f8-xwqj","description":"Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-59900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59900","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59900","date":"2026-10-08","epss":0.00398,"percentile":0.31911}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59900","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator maps `:authority` to `Host` and separately copies the literal `host` header, producing an `HttpRequest` object containing two `Host` headers with attacker-controlled differing values. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.16.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cqp-g7gg-8hr5","versionConstraint":">=4.2.0.Final,<4.2.16.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cqp-g7gg-8hr5","fix":{"state":"fixed","versions":["4.2.16.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.2.16.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"risk":0.2346,"urls":["https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5","https://nvd.nist.gov/vuln/detail/CVE-2026-56746","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cqp-g7gg-8hr5","description":"Netty: Security Control Bypass via CORS Short-Circuit Failure"},"relatedVulnerabilities":[{"id":"CVE-2026-56746","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56746","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56746","date":"2026-10-08","epss":0.00408,"percentile":0.32984}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56746","description":"Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2888","versionConstraint":"<1.21.11||>=1.22.0-0,<1.22.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2888","fix":{"state":"fixed","versions":["1.21.11","1.22.4"],"available":[{"date":"2024-06-04","kind":"release","version":"1.21.11"},{"date":"2024-06-04","kind":"release","version":"1.22.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24789","date":"2026-10-08","epss":0.00446,"percentile":0.36799}],"risk":0.23415000000000002,"urls":["https://go.dev/issue/66869","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/585397","description":"The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors."},"relatedVulnerabilities":[{"id":"CVE-2024-24789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24789","date":"2026-10-08","epss":0.00446,"percentile":0.36799}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/04/1","https://go.dev/cl/585397","https://go.dev/issue/66869","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5YAEIA6IUHUNGJ7AIXXPQT6D2GYENX7/","https://pkg.go.dev/vuln/GO-2024-2888","https://security.netapp.com/advisory/ntap-20250131-0008/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24789","description":"The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.19.0,<2.21.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","fix":{"state":"fixed","versions":["2.21.5"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"risk":0.228145,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties"},"relatedVulnerabilities":[{"id":"CVE-2026-54515","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4."}]},{"artifact":{"id":"1facc3e875c221a8","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"311ea62f27b26685b306dc24c4bbf765bc1950d9","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-handler-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.17.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fccg-mwvh-qqg4","versionConstraint":">=4.2.0.Final,<=4.2.16.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fccg-mwvh-qqg4","fix":{"state":"fixed","versions":["4.2.17.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.2.17.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"risk":0.22253,"urls":["https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4","https://nvd.nist.gov/vuln/detail/CVE-2026-75596","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fccg-mwvh-qqg4","description":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-75596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4980","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4980","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"risk":0.21811499999999998,"urls":["https://go.dev/cl/771180","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78981","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."},"relatedVulnerabilities":[{"id":"CVE-2026-39826","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"urls":["https://go.dev/cl/771180","https://go.dev/issue/78981","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4980"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39826","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4976","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4976","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"risk":0.212695,"urls":["https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/770541","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions.\n\nWhen used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function.\n\nFor example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."},"relatedVulnerabilities":[{"id":"CVE-2026-39825","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"urls":["https://go.dev/cl/770541","https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4976"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39825","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m4cv-j2px-7723","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m4cv-j2px-7723","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42580","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42580","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42580","date":"2026-10-08","epss":0.00362,"percentile":0.27988}],"risk":0.20815,"urls":["https://github.com/netty/netty/security/advisories/GHSA-m4cv-j2px-7723","https://nvd.nist.gov/vuln/detail/CVE-2026-42580"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m4cv-j2px-7723","description":"Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-42580","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42580","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42580","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42580","date":"2026-10-08","epss":0.00362,"percentile":0.27988}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-m4cv-j2px-7723"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42580","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4014","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4014","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"risk":0.20599499999999996,"urls":["https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709861","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."},"relatedVulnerabilities":[{"id":"CVE-2025-58183","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"urls":["https://go.dev/cl/709861","https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4014","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58183","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hvcg-qmg6-jm4c","versionConstraint":">=4.2.0.Final,<=4.2.14.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hvcg-qmg6-jm4c","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-16","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50020","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-50020","date":"2026-10-08","epss":0.00398,"percentile":0.3191}],"risk":0.20497,"urls":["https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c","https://nvd.nist.gov/vuln/detail/CVE-2026-50020","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hvcg-qmg6-jm4c","description":"Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted"},"relatedVulnerabilities":[{"id":"CVE-2026-50020","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50020","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-50020","date":"2026-10-08","epss":0.00398,"percentile":0.3191}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50020","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-93990"},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3503","versionConstraint":"<1.23.7||>=1.24.0-0,<1.24.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3503","fix":{"state":"fixed","versions":["1.23.7","1.24.1"],"available":[{"date":"2025-03-04","kind":"release","version":"1.23.7"},{"date":"2025-03-04","kind":"release","version":"1.24.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22870","cwe":"CWE-115","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22870","date":"2026-10-08","epss":0.00409,"percentile":0.33105}],"risk":0.19223,"urls":["https://go.dev/issue/71984","https://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/654697","description":"Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to \"*.example.com\", a request to \"[::1%25.example.com]:80` will incorrectly match and not be proxied."},"relatedVulnerabilities":[{"id":"CVE-2025-22870","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22870","cwe":"CWE-115","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22870","date":"2026-10-08","epss":0.00409,"percentile":0.33105}],"urls":["https://go.dev/cl/654697","https://go.dev/issue/71984","https://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ","https://pkg.go.dev/vuln/GO-2025-3503","http://www.openwall.com/lists/oss-security/2025/03/07/2","https://security.netapp.com/advisory/ntap-20250509-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22870","description":"Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to \"*.example.com\", a request to \"[::1%25.example.com]:80` will incorrectly match and not be proxied."},{"id":"GHSA-qxp5-gwg8-xv66","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22870","cwe":"CWE-115","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22870","date":"2026-10-08","epss":0.00409,"percentile":0.33105}],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-22870","https://go.dev/cl/654697","https://go.dev/issue/71984","https://pkg.go.dev/vuln/GO-2025-3503","http://www.openwall.com/lists/oss-security/2025/03/07/2","https://security.netapp.com/advisory/ntap-20250509-0007","https://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ"],"severity":"Medium","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-qxp5-gwg8-xv66","description":"HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net"}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4603","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4603","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"risk":0.19202999999999998,"urls":["https://go.dev/issue/77954","https://go.dev/cl/752081"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\".\n\nA new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."},"relatedVulnerabilities":[{"id":"CVE-2026-27142","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"urls":["https://go.dev/cl/752081","https://go.dev/issue/77954","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4603"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27142","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hgj6-7826-r7m5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hgj6-7826-r7m5","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"risk":0.18952000000000002,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://nvd.nist.gov/vuln/detail/CVE-2026-54514"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hgj6-7826-r7m5","description":"jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)"},"relatedVulnerabilities":[{"id":"CVE-2026-54514","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"urls":["https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54514","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4865","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4865","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763762","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied.\n\nThese issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."},"relatedVulnerabilities":[{"id":"CVE-2026-32289","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/763762","https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4865"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32289","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4982","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4982","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/cl/769920","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78913","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-39823","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/769920","https://go.dev/issue/78913","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4982"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39823","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.8.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-84h7-rjj3-6jx4","versionConstraint":">=4.2.0.Alpha1,<4.2.8.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-84h7-rjj3-6jx4","fix":{"state":"fixed","versions":["4.2.8.Final"],"available":[{"date":"2025-12-16","kind":"first-observed","version":"4.2.8.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-67735","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-67735","date":"2026-10-08","epss":0.0032,"percentile":0.23025}],"risk":0.184,"urls":["https://github.com/netty/netty/security/advisories/GHSA-84h7-rjj3-6jx4","https://github.com/netty/netty/commit/77e81f1e5944d98b3acf887d3aa443b252752e94","https://nvd.nist.gov/vuln/detail/CVE-2025-67735"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-84h7-rjj3-6jx4","description":"Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder"},"relatedVulnerabilities":[{"id":"CVE-2025-67735","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-67735","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-67735","date":"2026-10-08","epss":0.0032,"percentile":0.23025}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-84h7-rjj3-6jx4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-67735","description":"Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue."}]},{"artifact":{"id":"82bd49e59e12c322","cpes":["cpe:2.3:a:org.eclipse.jetty.server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:12.0.27:*:*:*:*:*:*:*"],"name":"jetty-server","purl":"pkg:maven/org.eclipse.jetty/jetty-server@12.0.27","type":"java-archive","version":"12.0.27","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","manifestName":"","pomArtifactID":"jetty-server","archiveDigests":[{"value":"65f40754e873638394ff06df7410f30967d15fdd","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.36"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f4v5-65jj-pcr2","versionConstraint":">=12.0.0,<=12.0.35 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-server","version":"12.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-f4v5-65jj-pcr2","fix":{"state":"fixed","versions":["12.0.36"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"12.0.36"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10051","cwe":"CWE-200","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-10051","date":"2026-10-08","epss":0.00302,"percentile":0.2105}],"risk":0.17969,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-f4v5-65jj-pcr2","https://nvd.nist.gov/vuln/detail/CVE-2026-10051","https://github.com/jetty/jetty.project/pull/15162","https://github.com/jetty/jetty.project/pull/15163","https://github.com/jetty/jetty.project/commit/72206b3ea623cf7ed8729b47a83ee628ff10e8eb","https://github.com/jetty/jetty.project/commit/dc27e8d3ab743fe27935ea2d8c41756eb6c5bae9","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f4v5-65jj-pcr2","description":"Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections"},"relatedVulnerabilities":[{"id":"CVE-2026-10051","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10051","cwe":"CWE-200","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-10051","date":"2026-10-08","epss":0.00302,"percentile":0.2105}],"urls":["https://gitlab.eclipse.org/security/cve-assignment/-/work_items/119"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10051","description":"In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection.\nSubsequent request that do not have trailers report the trailers of the first request.\nSubsequent request that do have trailers report the union of trailers of the first request and the current request."}]},{"artifact":{"id":"14cfe0f375d6d1af","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.2?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.2","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4970","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4970","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"risk":0.17748,"urls":["https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://go.dev/cl/797880"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79005","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.\n\nFor example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."},"relatedVulnerabilities":[{"id":"CVE-2026-39822","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"urls":["https://go.dev/cl/797880","https://go.dev/issue/79005","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-4970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.174,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102633"},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v8h7-rr48-vmmv","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-v8h7-rr48-vmmv","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-06","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41417","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41417","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41417","date":"2026-10-08","epss":0.00336,"percentile":0.2491}],"risk":0.17304000000000003,"urls":["https://github.com/netty/netty/security/advisories/GHSA-v8h7-rr48-vmmv","https://nvd.nist.gov/vuln/detail/CVE-2026-41417"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v8h7-rr48-vmmv","description":"Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection"},"relatedVulnerabilities":[{"id":"CVE-2026-41417","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41417","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41417","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41417","date":"2026-10-08","epss":0.00336,"percentile":0.2491}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-v8h7-rr48-vmmv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41417","description":"Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"748b07188747177f","cpes":["cpe:2.3:a:org.eclipse.jetty.util:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.util:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.util:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.util:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-util:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-util:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_util:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_util:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-util:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_util:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-util:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_util:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:util:jetty-util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:util:jetty_util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:util:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:util:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:util:util:12.0.27:*:*:*:*:*:*:*"],"name":"jetty-util","purl":"pkg:maven/org.eclipse.jetty/jetty-util@12.0.27","type":"java-archive","version":"12.0.27","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/opt/solr-10.0.0/server/lib/ext/jetty-util-12.0.27.jar","manifestName":"","pomArtifactID":"jetty-util","archiveDigests":[{"value":"1d1dac972fcd46ea9de83c2429bfa74c09438c84","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/jetty-util-12.0.27.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/jetty-util-12.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.35"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w7x5-g22v-xqhr","versionConstraint":">=12.0.0,<=12.0.34 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-util","version":"12.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-w7x5-g22v-xqhr","fix":{"state":"fixed","versions":["12.0.35"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"12.0.35"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8384","cwe":"CWE-647","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-8384","date":"2026-10-08","epss":0.0033,"percentile":0.24107}],"risk":0.16995000000000002,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-w7x5-g22v-xqhr","https://nvd.nist.gov/vuln/detail/CVE-2026-8384","https://github.com/jetty/jetty.project/pull/14969","https://github.com/jetty/jetty.project/pull/14973","https://github.com/jetty/jetty.project/commit/82969c77f6da46e27008b10b3c14840cd31db084","https://github.com/jetty/jetty.project/commit/ade27ce93a37c33278720250d85c48601230ae3f","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/108"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w7x5-g22v-xqhr","description":"Eclipse Jetty: Path parameter traversal"},"relatedVulnerabilities":[{"id":"CVE-2026-8384","cvss":[{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8384","cwe":"CWE-647","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-8384","date":"2026-10-08","epss":0.0033,"percentile":0.24107}],"urls":["https://gitlab.eclipse.org/security/cve-assignment/-/work_items/108"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8384","description":"In Eclipse Jetty, an HTTP URI of this form:\n\n\n\n\n\n/public;/../admin/secret.txt\n\n\n\n\n\n\n\n\nresults in an unresolved path of:\n\n\n\n\n\n/public/../admin/secret.txt\n\n\n\n\n\n\n\n\ninstead of the expected:\n\n\n\n\n\n/admin/secret.txt\n\n\n\n\n\n\n\n\nJetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served).\n\n\n\n\nHowever, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4340","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4340","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"risk":0.169435,"urls":["https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/724120","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-61730","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"urls":["https://go.dev/cl/724120","https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4340"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61730","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.13.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-38f8-5428-x5cv","versionConstraint":">=4.2.0.Alpha1,<=4.2.12.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-38f8-5428-x5cv","fix":{"state":"fixed","versions":["4.2.13.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.2.13.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42585","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42585","date":"2026-10-08","epss":0.00293,"percentile":0.20036}],"risk":0.16847499999999999,"urls":["https://github.com/netty/netty/security/advisories/GHSA-38f8-5428-x5cv","https://datatracker.ietf.org/doc/html/rfc9112#name-message-body-length","https://nvd.nist.gov/vuln/detail/CVE-2026-42585"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-38f8-5428-x5cv","description":"Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding"},"relatedVulnerabilities":[{"id":"CVE-2026-42585","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42585","cwe":"CWE-444","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42585","date":"2026-10-08","epss":0.00293,"percentile":0.20036}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-38f8-5428-x5cv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42585","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4864","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4864","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"risk":0.16644,"urls":["https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763761","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root.\n\nThe Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."},"relatedVulnerabilities":[{"id":"CVE-2026-32282","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"urls":["https://go.dev/cl/763761","https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4864"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32282","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3750","versionConstraint":"<1.23.10||>=1.24.0-0,<1.24.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3750","fix":{"state":"fixed","versions":["1.23.10","1.24.4"],"available":[{"date":"2025-06-05","kind":"release","version":"1.23.10"},{"date":"2025-06-05","kind":"release","version":"1.24.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0913","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-0913","date":"2026-10-08","epss":0.00314,"percentile":0.22305}],"risk":0.16485,"urls":["https://go.dev/issue/73702","https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/672396","description":"os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink."},"relatedVulnerabilities":[{"id":"CVE-2025-0913","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0913","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-0913","date":"2026-10-08","epss":0.00314,"percentile":0.22305}],"urls":["https://go.dev/cl/672396","https://go.dev/issue/73702","https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A","https://pkg.go.dev/vuln/GO-2025-3750"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0913","description":"os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4175","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4175","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"risk":0.1633,"urls":["https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/723900","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."},"relatedVulnerabilities":[{"id":"CVE-2025-61727","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"urls":["https://go.dev/cl/723900","https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4175"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61727","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."}]},{"artifact":{"id":"0040f8372be2723d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.20.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.20.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.0","type":"java-archive","version":"2.20.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"f0a5e62fbd21285e9a5498a60dccb097e1ef793b","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/jackson-databind-2.20.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vvgp-rfg2-7rr6","versionConstraint":">=2.19.0,<2.21.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.20.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vvgp-rfg2-7rr6","fix":{"state":"fixed","versions":["2.21.5"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"risk":0.161195,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6","https://nvd.nist.gov/vuln/detail/CVE-2026-77310","https://github.com/FasterXML/jackson-databind/pull/6058","https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vvgp-rfg2-7rr6","description":"jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-77310","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77310","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"82bd49e59e12c322","cpes":["cpe:2.3:a:org.eclipse.jetty.server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:server:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:12.0.27:*:*:*:*:*:*:*"],"name":"jetty-server","purl":"pkg:maven/org.eclipse.jetty/jetty-server@12.0.27","type":"java-archive","version":"12.0.27","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","manifestName":"","pomArtifactID":"jetty-server","archiveDigests":[{"value":"65f40754e873638394ff06df7410f30967d15fdd","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/jetty-server-12.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.35"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7p3p-8qv8-m2vh","versionConstraint":">=12.0.0,<=12.0.34 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-server","version":"12.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7p3p-8qv8-m2vh","fix":{"state":"fixed","versions":["12.0.35"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"12.0.35"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6790","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-6790","date":"2026-10-08","epss":0.0031,"percentile":0.21898}],"risk":0.15965000000000001,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh","https://nvd.nist.gov/vuln/detail/CVE-2026-6790","https://github.com/jetty/jetty.project/issues/14870","https://github.com/jetty/jetty.project/pull/14871","https://github.com/jetty/jetty.project/pull/14897","https://github.com/jetty/jetty.project/pull/14970","https://github.com/jetty/jetty.project/commit/3e5a4daec196859b8886b6f67b1157dab47cdb6f","https://github.com/jetty/jetty.project/commit/67ba9e6b39661810123680d9c894e99a7940c73d","https://github.com/jetty/jetty.project/commit/cbca3076f7c914a232e7a8b22fa95fbf7e67a6cc","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7p3p-8qv8-m2vh","description":"Eclipse Jetty: HTTP Authority/Host mismatch"},"relatedVulnerabilities":[{"id":"CVE-2026-6790","cvss":[{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6790","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-6790","date":"2026-10-08","epss":0.0031,"percentile":0.21898}],"urls":["https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6790","description":"In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present).\n\n\n\n\nThis was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112).\n\n\n\n\nThis mismatch can cause a number of problems that may be classified as vulnerabilities such as:\n\n\n\n  *  \n        \n      URI constructions (for example, for redirects -- this is typical for login pages)\n\n  *  \n        \n      Virtual host selection\n\n  *  \n        \n      Reverse proxying\n\n  *  \n        \n      Misleading logs\n\n  *  \n        \n      Etc.\n\n\n\n\n\n\nGiven that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"6962e55eff6f21a0","cpes":["cpe:2.3:a:io.netty.codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec-http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec_http:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec_http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec-http:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec_http:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-codec-http","purl":"pkg:maven/io.netty/netty-codec-http@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","manifestName":"","pomArtifactID":"netty-codec-http","archiveDigests":[{"value":"26da0fb9215bde2ecd551b941ccb974f65f59884","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/opentelemetry/lib/netty-codec-http-4.2.6.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.17.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8c42-7qj2-3j46","versionConstraint":">=4.2.0.Final,<=4.2.16.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec-http","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-8c42-7qj2-3j46","fix":{"state":"fixed","versions":["4.2.17.Final"],"available":[{"date":"2026-08-18","kind":"first-observed","version":"4.2.17.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"risk":0.14145,"urls":["https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8c42-7qj2-3j46","description":"Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite"},"relatedVulnerabilities":[{"id":"CVE-2026-59903","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59903","cwe":"CWE-524","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59903","date":"2026-10-08","epss":0.00246,"percentile":0.1453}],"urls":["https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59903","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d89ef5f93ba22208","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"dbc0224a08459408","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"8213e07a58a8ec78","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.7?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"16e6be2ba255a19b","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3447","versionConstraint":"<1.22.12||>=1.23.0-0,<1.23.6||>=1.24.0-0,<1.24.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3447","fix":{"state":"fixed","versions":["1.22.12","1.23.6","1.24.0-rc.3"],"available":[{"date":"2025-02-04","kind":"release","version":"1.22.12"},{"date":"2025-02-04","kind":"release","version":"1.23.6"},{"date":"2025-02-05","kind":"release","version":"1.24.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22866","date":"2026-10-08","epss":0.0029,"percentile":0.19736}],"risk":0.1305,"urls":["https://go.dev/issue/71383","https://groups.google.com/g/golang-announce/c/xU1ZCHUZw3k"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/643735","description":"Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols."},"relatedVulnerabilities":[{"id":"CVE-2025-22866","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22866","date":"2026-10-08","epss":0.0029,"percentile":0.19736}],"urls":["https://go.dev/cl/643735","https://go.dev/issue/71383","https://groups.google.com/g/golang-announce/c/xU1ZCHUZw3k","https://pkg.go.dev/vuln/GO-2025-3447","https://security.netapp.com/advisory/ntap-20250221-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22866","description":"Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols."}]},{"artifact":{"id":"cd80a8862611238d","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.3:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.3","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-16599","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-16599","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"risk":0.11249999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-16599"},"relatedVulnerabilities":[{"id":"CVE-2026-16599","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"urls":["https://cert.pl/en/posts/2026/08/CVE-2026-16599","https://gitlab.com/gnuwget/wget","https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16599","description":"GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.1015,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66382"},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4869","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4869","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"risk":0.09555000000000001,"urls":["https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763766","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."},"relatedVulnerabilities":[{"id":"CVE-2026-32288","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"urls":["https://go.dev/cl/763766","https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4869"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32288","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"66f54d89b7a27eab","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.13.2\\+dfsg-1ubuntu0.1:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/ubuntu/libfreetype6@2.13.2%2Bdfsg-1ubuntu0.1?arch=amd64&distro=ubuntu-24.04&upstream=freetype","type":"deb","version":"2.13.2+dfsg-1ubuntu0.1","language":"","licenses":["BSD-3-Clause","BSL-1.0","Expat","FSFAP","FTL","GPL-2","GPL-2+","GPL-3","GPL-3+","MIT-Modern-Variant","MIT-SMC","OpenGroup-MIT","Public-Domain","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.13.2+dfsg-1ubuntu0.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95512","versionConstraint":"< 2.13.2+dfsg-1ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"freetype","version":"2.13.2+dfsg-1ubuntu0.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95512","fix":{"state":"fixed","versions":["2.13.2+dfsg-1ubuntu0.2"],"available":[{"date":"2026-10-06","kind":"advisory","version":"2.13.2+dfsg-1ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"risk":0.087,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95512"},"relatedVulnerabilities":[{"id":"CVE-2026-95512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"urls":["https://access.redhat.com/errata/RHSA-2026:74952","https://access.redhat.com/security/cve/CVE-2026-95512","https://bugzilla.redhat.com/show_bug.cgi?id=2462295","https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."}]},{"artifact":{"id":"97ff31f30f666ac3","cpes":["cpe:2.3:a:io.netty.transport-native-epoll.linux-x86_64:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.transport-native-epoll.linux-x86_64:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.transport-native-epoll.linux-x86_64:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.transport-native-epoll.linux-x86_64:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native-epoll:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native-epoll:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native_epoll:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native_epoll:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native-epoll:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native-epoll:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native_epoll:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native_epoll:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native-epoll:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native-epoll:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native_epoll:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native_epoll:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport-native:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport_native:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native-epoll:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native-epoll:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native_epoll:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native_epoll:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86-64:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86-64:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86_64:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86_64:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86_64:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86_64:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport-native:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport_native:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-transport:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_transport:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86-64:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86-64:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86_64:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86_64:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86_64:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86_64:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux-x86:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux_x86:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:transport:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:linux:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:transport-native-epoll:4.2.6.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:transport_native_epoll:4.2.6.Final:*:*:*:*:*:*:*"],"name":"netty-transport-native-epoll","purl":"pkg:maven/io.netty/netty-transport-native-epoll@4.2.6.Final","type":"java-archive","version":"4.2.6.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-transport-native-epoll-4.2.6.Final-linux-x86_64.jar","manifestName":"","pomArtifactID":"netty-transport-native-epoll","archiveDigests":[{"value":"c4a2ba3782e65b34bbb54c3a6636b466955dc1c6","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-transport-native-epoll-4.2.6.Final-linux-x86_64.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/solr-webapp/webapp/WEB-INF/lib/netty-transport-native-epoll-4.2.6.Final-linux-x86_64.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.2.15.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w573-9ffj-6ff9","versionConstraint":">=4.2.0.Final,<=4.2.14.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-transport-native-epoll","version":"4.2.6.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-w573-9ffj-6ff9","fix":{"state":"fixed","versions":["4.2.15.Final"],"available":[{"date":"2026-06-09","kind":"first-observed","version":"4.2.15.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45536","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45536","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45536","date":"2026-10-08","epss":0.00193,"percentile":0.0815}],"risk":0.08685,"urls":["https://github.com/netty/netty/security/advisories/GHSA-w573-9ffj-6ff9","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-45536"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w573-9ffj-6ff9","description":"Netty: Unix-socket fd receive leaks descriptors when peer sends two at once"},"relatedVulnerabilities":[{"id":"CVE-2026-45536","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45536","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45536","cwe":"CWE-772","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45536","date":"2026-10-08","epss":0.00193,"percentile":0.0815}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-w573-9ffj-6ff9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45536","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4403","versionConstraint":"<1.23.9||>=1.24.0-0,<1.24.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4403","fix":{"state":"fixed","versions":["1.23.9","1.24.3"],"available":[{"date":"2025-05-06","kind":"release","version":"1.23.9"},{"date":"2025-05-06","kind":"release","version":"1.24.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","metrics":{"baseScore":3.8,"impactScore":1.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22873","cwe":"CWE-23","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22873","date":"2026-10-08","epss":0.00236,"percentile":0.13432}],"risk":0.08024,"urls":["https://go.dev/issue/73555","https://groups.google.com/g/golang-announce/c/UZoIkUT367A/m/5WDxKizJAQAJ"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/670036","description":"It was possible to improperly access the parent directory of an os.Root by opening a filename ending in \"../\". For example, Root.Open(\"../\") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent."},"relatedVulnerabilities":[{"id":"CVE-2025-22873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","metrics":{"baseScore":3.8,"impactScore":1.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22873","cwe":"CWE-23","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22873","date":"2026-10-08","epss":0.00236,"percentile":0.13432}],"urls":["https://go.dev/cl/670036","https://go.dev/issue/73555","https://groups.google.com/g/golang-announce/c/UZoIkUT367A/m/5WDxKizJAQAJ","https://pkg.go.dev/vuln/GO-2026-4403","http://www.openwall.com/lists/oss-security/2025/05/06/2"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22873","description":"It was possible to improperly access the parent directory of an os.Root by opening a filename ending in \"../\". For example, Root.Open(\"../\") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"124c06eded876109","cpes":["cpe:2.3:a:acl:acl:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"acl","purl":"pkg:deb/ubuntu/acl@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/acl/copyright","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/share/doc/acl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/acl.md5sums","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/acl.list","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.list"},{"path":"/var/lib/dpkg/info/acl.postinst","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.postinst"},{"path":"/var/lib/dpkg/info/acl.postrm","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"6d19596d468636a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/modules/cross-dc/lib/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mcr4-qmvw-px4g","versionConstraint":">=1.7.0,<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mcr4-qmvw-px4g","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"risk":0.061419999999999995,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","https://nvd.nist.gov/vuln/detail/CVE-2026-106451","https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mcr4-qmvw-px4g","description":"yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user"},"relatedVulnerabilities":[{"id":"CVE-2026-106451","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"urls":["https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"124c06eded876109","cpes":["cpe:2.3:a:acl:acl:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"acl","purl":"pkg:deb/ubuntu/acl@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/acl/copyright","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/share/doc/acl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/acl.md5sums","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/acl.list","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.list"},{"path":"/var/lib/dpkg/info/acl.postinst","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.postinst"},{"path":"/var/lib/dpkg/info/acl.postrm","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/info/acl.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"cfbd19c60d7ed087","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:12.0.27:*:*:*:*:*:*:*","cpe:2.3:a:http:http:12.0.27:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@12.0.27","type":"java-archive","version":"12.0.27","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0/, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/opt/solr-10.0.0/server/lib/ext/jetty-http-12.0.27.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"a87f269dbac2a0aae6d9020b26e853bbe6bb8b8e","algorithm":"sha1"}]},"locations":[{"path":"/opt/solr-10.0.0/server/lib/ext/jetty-http-12.0.27.jar","layerID":"sha256:c98a2fd423f0081dcc6a59c7941237048c908586671e270886341654e8ad562d","accessPath":"/opt/solr-10.0.0/server/lib/ext/jetty-http-12.0.27.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjpw-4j6x-6rwh","versionConstraint":">=12.0.0,<=12.0.30 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"12.0.27"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjpw-4j6x-6rwh","fix":{"state":"fixed","versions":["12.0.31"],"available":[{"date":"2026-03-06","kind":"first-observed","version":"12.0.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2025-11143","date":"2026-10-08","epss":0.00161,"percentile":0.04733}],"risk":0.053935,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh","https://nvd.nist.gov/vuln/detail/CVE-2025-11143","https://github.com/user-attachments/files/22222625/Java.Eclipse.Jetty.Report_.Incorrect.Parsing.Priority.of.the.IPv6.Hostname.Delimeter.pdf","https://github.com/user-attachments/files/22222626/Java.Eclipse.Jetty.Report_.The.Parsing.Priority.of.the.Delimiter.pdf","https://github.com/user-attachments/files/22222627/Java.Eclipse.Jetty.Report_.Parsing.Difference.Due.to.Deformed.Scheme.pdf","https://github.com/user-attachments/files/22222630/Java.Eclipse.Jetty.Report_.Improper.IPv4-mapped.IPv6.Parsing.pdf"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjpw-4j6x-6rwh","description":"org.eclipse.jetty:jetty-http has different parsing of invalid URIs"},"relatedVulnerabilities":[{"id":"CVE-2025-11143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2025-11143","date":"2026-10-08","epss":0.00161,"percentile":0.04733}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11143","description":"The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details."}]},{"artifact":{"id":"17317631a09f6a3f","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"c37cad8d5a3a6548","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4602","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4602","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"risk":0.03245,"urls":["https://go.dev/issue/77827","https://go.dev/cl/749480"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened.\n\nThe impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."},"relatedVulnerabilities":[{"id":"CVE-2026-27139","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"urls":["https://go.dev/cl/749480","https://go.dev/issue/77827","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4602"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27139","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."}]},{"artifact":{"id":"01814745da17448f","cpes":["cpe:2.3:a:libpng16-16t64:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16t64:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*"],"name":"libpng16-16t64","purl":"pkg:deb/ubuntu/libpng16-16t64@1.6.43-5ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=libpng1.6","type":"deb","version":"1.6.43-5ubuntu0.6","language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16t64/copyright","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/usr/share/doc/libpng16-16t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","layerID":"sha256:e8b0be564a591c47cea8ab47e6cae52cb306e518925a559f9790746fa3086a90","accessPath":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libpng1.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46675","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libpng1.6","version":"1.6.43-5ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46675","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46675"},"relatedVulnerabilities":[{"id":"CVE-2026-46675","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"80e4606664de58be","cpes":["cpe:2.3:a:golang:go:1.22.2:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.22.2","type":"go-module","version":"go1.22.2","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.22.2"},"locations":[{"path":"/usr/sbin/gosu","layerID":"sha256:a222dda4578c2d38d835cf61e873dee41f0324330988fab6a7e43f8a3a7a4f19","accessPath":"/usr/sbin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.22.2"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:32:35.962Z","grype_db_version":"2026-10-09T06:32:32.000Z"}