{"grype_matches":[{"artifact":{"id":"7ad616ad1d6016c5","cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"name":"JRuby","purl":"","type":"binary","version":"1.0","language":"","licenses":[],"locations":[{"path":"/usr/share/logstash/vendor/jruby/bin/jruby.exe","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/bin/jruby.exe","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.5.1"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:jruby:jruby:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-4838","versionConstraint":"< 1.6.5.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"package":{"name":"JRuby","version":"1.0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-4838","fix":{"state":"fixed","versions":["1.6.5.1"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.6.5.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-4838","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4838","date":"2026-10-08","epss":0.04203,"percentile":0.90704}],"risk":2.1014999999999997,"urls":["http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html","http://jruby.org/2011/12/27/jruby-1-6-5-1.html","http://rhn.redhat.com/errata/RHSA-2012-1232.html","http://secunia.com/advisories/47407","http://secunia.com/advisories/50084","http://security.gentoo.org/glsa/glsa-201207-06.xml","http://www.kb.cert.org/vuls/id/903934","http://www.nruns.com/_downloads/advisory28122011.pdf","http://www.ocert.org/advisories/ocert-2011-003.html","https://exchange.xforce.ibmcloud.com/vulnerabilities/72019"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4838","description":"JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table."},"relatedVulnerabilities":[]},{"artifact":{"id":"0556204216c3d046","cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"name":"JRuby","purl":"","type":"binary","version":"1.0","language":"","licenses":[],"locations":[{"path":"/usr/share/logstash/vendor/jruby/bin/jrubyw.exe","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/bin/jrubyw.exe","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.6.5.1"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:jruby:jruby:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-4838","versionConstraint":"< 1.6.5.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"package":{"name":"JRuby","version":"1.0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-4838","fix":{"state":"fixed","versions":["1.6.5.1"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.6.5.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-4838","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4838","date":"2026-10-08","epss":0.04203,"percentile":0.90704}],"risk":2.1014999999999997,"urls":["http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html","http://jruby.org/2011/12/27/jruby-1-6-5-1.html","http://rhn.redhat.com/errata/RHSA-2012-1232.html","http://secunia.com/advisories/47407","http://secunia.com/advisories/50084","http://security.gentoo.org/glsa/glsa-201207-06.xml","http://www.kb.cert.org/vuls/id/903934","http://www.nruns.com/_downloads/advisory28122011.pdf","http://www.ocert.org/advisories/ocert-2011-003.html","https://exchange.xforce.ibmcloud.com/vulnerabilities/72019"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4838","description":"JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table."},"relatedVulnerabilities":[]},{"artifact":{"id":"7ad616ad1d6016c5","cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"name":"JRuby","purl":"","type":"binary","version":"1.0","language":"","licenses":[],"locations":[{"path":"/usr/share/logstash/vendor/jruby/bin/jruby.exe","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/bin/jruby.exe","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:jruby:jruby:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2012-5370","versionConstraint":"none (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"package":{"name":"JRuby","version":"1.0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2012-5370","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2012-5370","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2012-5370","date":"2026-10-08","epss":0.02249,"percentile":0.82368}],"risk":1.1245,"urls":["http://2012.appsec-forum.ch/conferences/#c17","http://asfws12.files.wordpress.com/2012/11/asfws2012-jean_philippe_aumasson-martin_bosslet-hash_flooding_dos_reloaded.pdf","http://rhn.redhat.com/errata/RHSA-2013-0533.html","http://www.ocert.org/advisories/ocert-2012-001.html","https://bugzilla.redhat.com/show_bug.cgi?id=880671","https://www.131002.net/data/talks/appsec12_slides.pdf"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5370","description":"JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838."},"relatedVulnerabilities":[]},{"artifact":{"id":"0556204216c3d046","cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"name":"JRuby","purl":"","type":"binary","version":"1.0","language":"","licenses":[],"locations":[{"path":"/usr/share/logstash/vendor/jruby/bin/jrubyw.exe","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/bin/jrubyw.exe","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:jruby:jruby:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2012-5370","versionConstraint":"none (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"package":{"name":"JRuby","version":"1.0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2012-5370","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2012-5370","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2012-5370","date":"2026-10-08","epss":0.02249,"percentile":0.82368}],"risk":1.1245,"urls":["http://2012.appsec-forum.ch/conferences/#c17","http://asfws12.files.wordpress.com/2012/11/asfws2012-jean_philippe_aumasson-martin_bosslet-hash_flooding_dos_reloaded.pdf","http://rhn.redhat.com/errata/RHSA-2013-0533.html","http://www.ocert.org/advisories/ocert-2012-001.html","https://bugzilla.redhat.com/show_bug.cgi?id=880671","https://www.131002.net/data/talks/appsec12_slides.pdf"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-5370","description":"JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838."},"relatedVulnerabilities":[]},{"artifact":{"id":"7ad616ad1d6016c5","cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"name":"JRuby","purl":"","type":"binary","version":"1.0","language":"","licenses":[],"locations":[{"path":"/usr/share/logstash/vendor/jruby/bin/jruby.exe","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/bin/jruby.exe","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:jruby:jruby:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2010-1330","versionConstraint":"<= 1.4.0||= 0.9.0||= 0.9.1||= 0.9.2||= 0.9.8||= 0.9.9||= 1.0.0||= 1.0.0-rc1||= 1.0.0-rc2||= 1.0.0-rc3||= 1.0.1||= 1.0.2||= 1.0.3||= 1.1||= 1.1-beta1||= 1.1-rc1||= 1.1-rc2||= 1.1-rc3||= 1.1.1||= 1.1.2||= 1.1.3||= 1.1.4||= 1.1.5||= 1.1.6||= 1.1.6-rc1||= 1.2.0||= 1.2.0-rc1||= 1.2.0-rc2||= 1.3.0||= 1.3.0-rc1||= 1.3.0-rc2||= 1.3.1||= 1.4.0-rc1||= 1.4.0-rc2||= 1.4.0-rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"package":{"name":"JRuby","version":"1.0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2010-1330","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-1330","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-1330","date":"2026-10-08","epss":0.02218,"percentile":0.82118}],"risk":1.03137,"urls":["http://rhn.redhat.com/errata/RHSA-2011-1456.html","http://secunia.com/advisories/46891","http://www.jruby.org/2010/04/26/jruby-1-4-1-xss-vulnerability.html","http://www.osvdb.org/77297","https://bugs.gentoo.org/show_bug.cgi?id=317435","https://bugzilla.redhat.com/show_bug.cgi?id=750306","https://exchange.xforce.ibmcloud.com/vulnerabilities/80277"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-1330","description":"The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string."},"relatedVulnerabilities":[]},{"artifact":{"id":"0556204216c3d046","cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"name":"JRuby","purl":"","type":"binary","version":"1.0","language":"","licenses":[],"locations":[{"path":"/usr/share/logstash/vendor/jruby/bin/jrubyw.exe","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/bin/jrubyw.exe","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:jruby:jruby:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2010-1330","versionConstraint":"<= 1.4.0||= 0.9.0||= 0.9.1||= 0.9.2||= 0.9.8||= 0.9.9||= 1.0.0||= 1.0.0-rc1||= 1.0.0-rc2||= 1.0.0-rc3||= 1.0.1||= 1.0.2||= 1.0.3||= 1.1||= 1.1-beta1||= 1.1-rc1||= 1.1-rc2||= 1.1-rc3||= 1.1.1||= 1.1.2||= 1.1.3||= 1.1.4||= 1.1.5||= 1.1.6||= 1.1.6-rc1||= 1.2.0||= 1.2.0-rc1||= 1.2.0-rc2||= 1.3.0||= 1.3.0-rc1||= 1.3.0-rc2||= 1.3.1||= 1.4.0-rc1||= 1.4.0-rc2||= 1.4.0-rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:JRuby:JRuby:1.0:*:*:*:*:*:*:*"],"package":{"name":"JRuby","version":"1.0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2010-1330","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-1330","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-1330","date":"2026-10-08","epss":0.02218,"percentile":0.82118}],"risk":1.03137,"urls":["http://rhn.redhat.com/errata/RHSA-2011-1456.html","http://secunia.com/advisories/46891","http://www.jruby.org/2010/04/26/jruby-1-4-1-xss-vulnerability.html","http://www.osvdb.org/77297","https://bugs.gentoo.org/show_bug.cgi?id=317435","https://bugzilla.redhat.com/show_bug.cgi?id=750306","https://exchange.xforce.ibmcloud.com/vulnerabilities/80277"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-1330","description":"The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string."},"relatedVulnerabilities":[]},{"artifact":{"id":"c3e10f285acbebe8","cpes":["cpe:2.3:a:ruby-lang:net\\:\\:imap:0.2.5:*:*:*:*:ruby:*:*"],"name":"net-imap","purl":"pkg:gem/net-imap@0.2.5","type":"gem","version":"0.2.5","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.4.24"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-75xq-5h9v-w6px","versionConstraint":">=0,<=0.4.23 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"net-imap","version":"0.2.5"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-75xq-5h9v-w6px","fix":{"state":"fixed","versions":["0.4.24"],"available":[{"date":"2026-05-05","kind":"first-observed","version":"0.4.24"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42258","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42258","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42258","cwe":"CWE-93","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42258","date":"2026-10-08","epss":0.01253,"percentile":0.68554}],"risk":0.6609575,"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px","https://github.com/ruby/net-imap/commit/6bf02aef7e0b5931010c36e377f79a71636b306b","https://github.com/ruby/net-imap/commit/9db3e9d60bfb8f3735ea95015bf8a700f4af9cbb","https://github.com/ruby/net-imap/commit/aec06996eb87a7e1bbcef1f9f8926e8add2b8c71","https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/releases/tag/v0.6.4","https://nvd.nist.gov/vuln/detail/CVE-2026-42258","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-42258.yml","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json","https://bugzilla.redhat.com/show_bug.cgi?id=2468498","https://access.redhat.com/security/cve/CVE-2026-42258","https://access.redhat.com/errata/RHSA-2026:37397","https://access.redhat.com/errata/RHSA-2026:37238","https://access.redhat.com/errata/RHSA-2026:36978","https://access.redhat.com/errata/RHSA-2026:36099","https://access.redhat.com/errata/RHSA-2026:35895","https://access.redhat.com/errata/RHSA-2026:35867","https://access.redhat.com/errata/RHSA-2026:35866","https://access.redhat.com/errata/RHSA-2026:35834","https://access.redhat.com/errata/RHSA-2026:35447","https://access.redhat.com/errata/RHSA-2026:34076","https://access.redhat.com/errata/RHSA-2026:33721","https://access.redhat.com/errata/RHSA-2026:33630","https://access.redhat.com/errata/RHSA-2026:33577","https://access.redhat.com/errata/RHSA-2026:33576","https://access.redhat.com/errata/RHSA-2026:33565","https://access.redhat.com/errata/RHSA-2026:33540","https://access.redhat.com/errata/RHSA-2026:33515","https://access.redhat.com/errata/RHSA-2026:33514","https://access.redhat.com/errata/RHSA-2026:33512","https://access.redhat.com/errata/RHSA-2026:33462","https://access.redhat.com/errata/RHSA-2026:38694","https://access.redhat.com/errata/RHSA-2026:40380"],"severity":"Medium","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-75xq-5h9v-w6px","description":"net-imap vulnerable to command Injection via unvalidated Symbol inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-42258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42258","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42258","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42258","cwe":"CWE-93","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42258","date":"2026-10-08","epss":0.01253,"percentile":0.68554}],"urls":["https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/releases/tag/v0.6.4","https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px","https://access.redhat.com/errata/RHSA-2026:33462","https://access.redhat.com/errata/RHSA-2026:33512","https://access.redhat.com/errata/RHSA-2026:33514","https://access.redhat.com/errata/RHSA-2026:33515","https://access.redhat.com/errata/RHSA-2026:33540","https://access.redhat.com/errata/RHSA-2026:33565","https://access.redhat.com/errata/RHSA-2026:33576","https://access.redhat.com/errata/RHSA-2026:33577","https://access.redhat.com/errata/RHSA-2026:33630","https://access.redhat.com/errata/RHSA-2026:34076","https://access.redhat.com/errata/RHSA-2026:35834","https://access.redhat.com/errata/RHSA-2026:35866","https://access.redhat.com/errata/RHSA-2026:35867","https://access.redhat.com/errata/RHSA-2026:35895","https://access.redhat.com/errata/RHSA-2026:36099","https://access.redhat.com/errata/RHSA-2026:36978","https://access.redhat.com/errata/RHSA-2026:37238","https://access.redhat.com/errata/RHSA-2026:37397","https://access.redhat.com/errata/RHSA-2026:38694","https://access.redhat.com/errata/RHSA-2026:40380","https://access.redhat.com/security/cve/CVE-2026-42258","https://bugzilla.redhat.com/show_bug.cgi?id=2468498","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42258.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42258","description":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4."}]},{"artifact":{"id":"c3e10f285acbebe8","cpes":["cpe:2.3:a:ruby-lang:net\\:\\:imap:0.2.5:*:*:*:*:ruby:*:*"],"name":"net-imap","purl":"pkg:gem/net-imap@0.2.5","type":"gem","version":"0.2.5","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.5.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8p34-64r3-mwg8","versionConstraint":"<=0.5.14 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"net-imap","version":"0.2.5"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-8p34-64r3-mwg8","fix":{"state":"fixed","versions":["0.5.15"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"0.5.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47240","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47240","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47240","date":"2026-10-08","epss":0.00831,"percentile":0.56275}],"risk":0.44873999999999997,"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-8p34-64r3-mwg8","https://github.com/ruby/net-imap/releases/tag/v0.6.4.1","https://nvd.nist.gov/vuln/detail/CVE-2026-47240","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-47240.yml","https://www.cve.org/CVERecord?id=CVE-2026-47240"],"severity":"Medium","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8p34-64r3-mwg8","description":"Net::IMAP: Command Injection via non-synchronizing literal in \"raw\" argument"},"relatedVulnerabilities":[{"id":"CVE-2026-47240","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47240","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47240","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47240","date":"2026-10-08","epss":0.00831,"percentile":0.56275}],"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-8p34-64r3-mwg8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47240","description":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a \"raw data\" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals.  A server without support for non-synchronizing literals may interpret the \"+}\\r\\n\" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed. This affects criteria for #search and #uid_search; search_keys for #sort, #thread, #uid_sort, and #uid_thread; and attr for #fetch and #uid_fetch. This vulnerability is fixed in 0.6.5 and 0.5.15."}]},{"artifact":{"id":"2a481d07aff64efa","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.14.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"a4600ce2bd4fe071","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.17.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"0bffb174a4f92601","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.17.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"b5b44bf2058740f6","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"7a71e4eeb27e88ba462f8f085afd3e4ec6ecadf0","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"cd5dfd658167c184","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"7a71e4eeb27e88ba462f8f085afd3e4ec6ecadf0","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"cd695a06c26d379b","cpes":["cpe:2.3:a:jackson-core:jackson-core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:3.1.6:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/tools.jackson.core/jackson-core@3.1.6","type":"java-archive","version":"3.1.6","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:tools.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-core","version":"3.1.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"8d004ede87638e78","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.84:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.84","type":"java-archive","version":"1.84","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"2d5651789941d2f8ae9b8771f23356de6b61e96b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.85"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9pwp-9qqc-pr26","versionConstraint":"<1.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.84"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9pwp-9qqc-pr26","fix":{"state":"fixed","versions":["1.85"],"available":[{"date":"2026-09-19","kind":"first-observed","version":"1.85"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8763","cwe":"CWE-295","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-8763","date":"2026-10-08","epss":0.0043,"percentile":0.35225}],"risk":0.3913,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-8763","https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558","https://github.com/bcgit/bc-java/wiki/CVE-2026-8763","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763","https://github.com/bcgit/bc-java/releases/tag/r1rv85v2"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9pwp-9qqc-pr26","description":"Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI"},"relatedVulnerabilities":[{"id":"CVE-2026-8763","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8763","cwe":"CWE-295","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-8763","date":"2026-10-08","epss":0.0043,"percentile":0.35225}],"urls":["https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8763","description":"In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series)."}]},{"artifact":{"id":"2a481d07aff64efa","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.11.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4rq-3m3g-8wgx","versionConstraint":"<1.19.3 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-c4rq-3m3g-8wgx","fix":{"state":"fixed","versions":["1.19.3"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"1.19.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79770","cwe":"CWE-1333","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-79770","date":"2026-10-08","epss":0.00493,"percentile":0.40408}],"risk":0.36975,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-c4rq-3m3g-8wgx","https://nvd.nist.gov/vuln/detail/CVE-2026-79770","https://www.vulncheck.com/advisories/nokogiri-before-redos-via-css-selector-tokenizer"],"severity":"High","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4rq-3m3g-8wgx","description":"Nokogiri CSS selector tokenizer has regular expression backtracking"},"relatedVulnerabilities":[{"id":"CVE-2026-79770","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79770","cwe":"CWE-1333","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-79770","date":"2026-10-08","epss":0.00493,"percentile":0.40408}],"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-c4rq-3m3g-8wgx","https://www.vulncheck.com/advisories/nokogiri-before-redos-via-css-selector-tokenizer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79770","description":"Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service."}]},{"artifact":{"id":"0bffb174a4f92601","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"a4600ce2bd4fe071","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"b5b44bf2058740f6","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"7a71e4eeb27e88ba462f8f085afd3e4ec6ecadf0","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"cd5dfd658167c184","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"7a71e4eeb27e88ba462f8f085afd3e4ec6ecadf0","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-core/2.21.6/jackson-core-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"cd695a06c26d379b","cpes":["cpe:2.3:a:jackson-core:jackson-core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:3.1.6:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/tools.jackson.core/jackson-core@3.1.6","type":"java-archive","version":"3.1.6","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:tools.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-core","version":"3.1.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"8d004ede87638e78","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.84:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.84:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.84","type":"java-archive","version":"1.84","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"2d5651789941d2f8ae9b8771f23356de6b61e96b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.85"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qp49-qgx5-5m26","versionConstraint":"<1.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.84"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qp49-qgx5-5m26","fix":{"state":"fixed","versions":["1.85"],"available":[{"date":"2026-09-19","kind":"first-observed","version":"1.85"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13506","cwe":"CWE-674","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-13506","date":"2026-10-08","epss":0.00442,"percentile":0.36375}],"risk":0.34476,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-13506","https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qp49-qgx5-5m26","description":"Bouncy Castle: Lazy ASN.1 sequence forcing resets nesting-depth guard"},"relatedVulnerabilities":[{"id":"CVE-2026-13506","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13506","cwe":"CWE-674","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-13506","date":"2026-10-08","epss":0.00442,"percentile":0.36375}],"urls":["https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13506","description":"In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series)."}]},{"artifact":{"id":"2a481d07aff64efa","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.5.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"2a481d07aff64efa","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.0.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"2348c4ddfd0c22b3","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"90fc0c39cc03058141d4312ccadb431a583d6574","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"b8faa918995a2f43","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"90fc0c39cc03058141d4312ccadb431a583d6574","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"b8faa918995a2f43","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"90fc0c39cc03058141d4312ccadb431a583d6574","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"2348c4ddfd0c22b3","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.21.6:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.21.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.6","type":"java-archive","version":"2.21.6","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"90fc0c39cc03058141d4312ccadb431a583d6574","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-azure_event_hubs-1.5.10/vendor/jar-dependencies/com/fasterxml/jackson/core/jackson-databind/2.21.6/jackson-databind-2.21.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.21.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"4ccd45287f66c7ec","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.1.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.1.6","type":"java-archive","version":"3.1.6","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.1.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"4ccd45287f66c7ec","cpes":["cpe:2.3:a:jackson-databind:jackson-databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:3.1.6:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:3.1.6:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/tools.jackson.core/jackson-databind@3.1.6","type":"java-archive","version":"3.1.6","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"tools.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:tools.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=3.0.0,<=3.1.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"tools.jackson.core:jackson-databind","version":"3.1.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["3.1.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"c3e10f285acbebe8","cpes":["cpe:2.3:a:ruby-lang:net\\:\\:imap:0.2.5:*:*:*:*:ruby:*:*"],"name":"net-imap","purl":"pkg:gem/net-imap@0.2.5","type":"gem","version":"0.2.5","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.4.24"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hm49-wcqc-g2xg","versionConstraint":">=0,<=0.4.23 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"net-imap","version":"0.2.5"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-hm49-wcqc-g2xg","fix":{"state":"fixed","versions":["0.4.24"],"available":[{"date":"2026-05-05","kind":"first-observed","version":"0.4.24"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42257","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42257","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42257","date":"2026-10-08","epss":0.00519,"percentile":0.42278}],"risk":0.28026,"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-hm49-wcqc-g2xg","https://github.com/ruby/net-imap/commit/0ec4fd351263e8b9a4f683713427827b7b1ad974","https://github.com/ruby/net-imap/commit/47c72186d272441878ca73c9499f66013829ca2f","https://github.com/ruby/net-imap/commit/6bf02aef7e0b5931010c36e377f79a71636b306b","https://github.com/ruby/net-imap/commit/a4f7649c3da77dec7631f03a037a478eb4330048","https://github.com/ruby/net-imap/commit/aec06996eb87a7e1bbcef1f9f8926e8add2b8c71","https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/releases/tag/v0.6.4","https://nvd.nist.gov/vuln/detail/CVE-2026-42257","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-42257.yml"],"severity":"Medium","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hm49-wcqc-g2xg","description":"net-imap vulnerable to command Injection via \"raw\" arguments to multiple commands"},"relatedVulnerabilities":[{"id":"CVE-2026-42257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42257","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42257","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42257","date":"2026-10-08","epss":0.00519,"percentile":0.42278}],"urls":["https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/releases/tag/v0.6.4","https://github.com/ruby/net-imap/security/advisories/GHSA-hm49-wcqc-g2xg"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42257","description":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4."}]},{"artifact":{"id":"2a481d07aff64efa","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.9:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.9:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.9","type":"java-archive","version":"2.18.9","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-filter-elastic_integration-8.19.10-java/vendor/jar-dependencies/co/elastic/logstash-filter-elastic_integration/8.19.10/logstash-filter-elastic_integration-8.19.10.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.8.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"b904e73d5a852202","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xx22-p4ch-683r","versionConstraint":"<=1.11.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xx22-p4ch-683r","fix":{"state":"fixed","versions":["1.11.1"],"available":[{"date":"2026-07-24","kind":"first-observed","version":"1.11.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"risk":0.26795,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r","https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xx22-p4ch-683r","description":"LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-59949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"urls":["https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1","https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59949","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1."}]},{"artifact":{"id":"c3e10f285acbebe8","cpes":["cpe:2.3:a:ruby-lang:net\\:\\:imap:0.2.5:*:*:*:*:ruby:*:*"],"name":"net-imap","purl":"pkg:gem/net-imap@0.2.5","type":"gem","version":"0.2.5","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.3.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vcgp-9326-pqcp","versionConstraint":">=0,<=0.3.9 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"net-imap","version":"0.2.5"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-vcgp-9326-pqcp","fix":{"state":"fixed","versions":["0.3.10"],"available":[{"date":"2026-05-05","kind":"first-observed","version":"0.3.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42246","cwe":"CWE-392","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-393","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-636","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-841","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-325","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42246","date":"2026-10-08","epss":0.00312,"percentile":0.22148}],"risk":0.23556,"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp","https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618","https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e","https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c","https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da","https://github.com/ruby/net-imap/releases/tag/v0.3.10","https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/releases/tag/v0.6.4","https://nostarttls.secvuln.info","https://www.rfc-editor.org/info/rfc8314","https://nvd.nist.gov/vuln/detail/CVE-2026-42246","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-42246.yml"],"severity":"High","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vcgp-9326-pqcp","description":"net-imap vulnerable to STARTTLS stripping via invalid response timing"},"relatedVulnerabilities":[{"id":"CVE-2026-42246","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42246","cwe":"CWE-392","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-393","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-636","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-841","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42246","cwe":"CWE-325","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42246","date":"2026-10-08","epss":0.00312,"percentile":0.22148}],"urls":["https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618","https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e","https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c","https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da","https://github.com/ruby/net-imap/releases/tag/v0.3.10","https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp","https://access.redhat.com/errata/RHSA-2026:33462","https://access.redhat.com/errata/RHSA-2026:33512","https://access.redhat.com/errata/RHSA-2026:33514","https://access.redhat.com/errata/RHSA-2026:33515","https://access.redhat.com/errata/RHSA-2026:33540","https://access.redhat.com/errata/RHSA-2026:33551","https://access.redhat.com/errata/RHSA-2026:33552","https://access.redhat.com/errata/RHSA-2026:33565","https://access.redhat.com/errata/RHSA-2026:33576","https://access.redhat.com/errata/RHSA-2026:33577","https://access.redhat.com/errata/RHSA-2026:33630","https://access.redhat.com/errata/RHSA-2026:33721","https://access.redhat.com/errata/RHSA-2026:34076","https://access.redhat.com/errata/RHSA-2026:35834","https://access.redhat.com/errata/RHSA-2026:35866","https://access.redhat.com/errata/RHSA-2026:35867","https://access.redhat.com/errata/RHSA-2026:35895","https://access.redhat.com/errata/RHSA-2026:36099","https://access.redhat.com/errata/RHSA-2026:37238","https://access.redhat.com/errata/RHSA-2026:37397","https://access.redhat.com/security/cve/CVE-2026-42246","https://bugzilla.redhat.com/show_bug.cgi?id=2468499","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42246","description":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return \"successfully\", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4."}]},{"artifact":{"id":"f0a11ce85261090f","cpes":["cpe:2.3:a:ruby-lang:uri:0.12.4:*:*:*:*:ruby:*:*"],"name":"uri","purl":"pkg:gem/uri@0.12.4","type":"gem","version":"0.12.4","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/default/uri-0.12.4.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/default/uri-0.12.4.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.12.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j4pr-3wm6-xx2r","versionConstraint":"<0.12.5 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"uri","version":"0.12.4"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-j4pr-3wm6-xx2r","fix":{"state":"fixed","versions":["0.12.5"],"available":[{"date":"2026-01-01","kind":"first-observed","version":"0.12.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":2.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61594","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-61594","cwe":"CWE-212","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-61594","date":"2026-10-08","epss":0.0056,"percentile":0.44823}],"risk":0.2268,"urls":["https://github.com/ruby/uri/commit/20157e3e29b125ff41f1d9662e2e3b1d066f5902","https://github.com/ruby/uri/commit/7e521b2da0833d964aab43019e735aea674e1c2c","https://github.com/ruby/uri/commit/d3116ca66a3b1c97dc7577f9d2d6e353f391cd6a","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2025-61594.yml","https://www.ruby-lang.org/en/news/2025/10/07/uri-cve-2025-61594","https://github.com/ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r","https://nvd.nist.gov/vuln/detail/CVE-2025-61594","https://hackerone.com/reports/2957667","https://github.com/advisories/GHSA-22h5-pq3x-2gf2","https://www.ruby-lang.org/en/news/2025/02/26/security-advisories"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j4pr-3wm6-xx2r","description":"URI Credential Leakage Bypass over CVE-2025-27221"},"relatedVulnerabilities":[{"id":"CVE-2025-61594","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61594","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-61594","cwe":"CWE-212","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-61594","date":"2026-10-08","epss":0.0056,"percentile":0.44823}],"urls":["https://github.com/advisories/GHSA-22h5-pq3x-2gf2","https://github.com/ruby/uri/security/advisories/GHSA-j4pr-3wm6-xx2r","https://hackerone.com/reports/2957667","https://www.ruby-lang.org/en/news/2025/02/26/security-advisories"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61594","description":"URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4."}]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v2fc-qm4h-8hqv","versionConstraint":"<1.19.3 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-v2fc-qm4h-8hqv","fix":{"state":"fixed","versions":["1.19.3"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"1.19.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79771","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-79771","date":"2026-10-08","epss":0.00423,"percentile":0.34575}],"risk":0.217845,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v2fc-qm4h-8hqv","https://nvd.nist.gov/vuln/detail/CVE-2026-79771","https://www.vulncheck.com/advisories/nokogiri-before-memory-leak-via-xslt-transform"],"severity":"Medium","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v2fc-qm4h-8hqv","description":"Nokogiri XSLT transform has a memory leak"},"relatedVulnerabilities":[{"id":"CVE-2026-79771","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79771","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-79771","date":"2026-10-08","epss":0.00423,"percentile":0.34575}],"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v2fc-qm4h-8hqv","https://www.vulncheck.com/advisories/nokogiri-before-memory-leak-via-xslt-transform"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79771","description":"Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"b904e73d5a852202","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"b904e73d5a852202","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"b904e73d5a852202","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"c3e10f285acbebe8","cpes":["cpe:2.3:a:ruby-lang:net\\:\\:imap:0.2.5:*:*:*:*:ruby:*:*"],"name":"net-imap","purl":"pkg:gem/net-imap@0.2.5","type":"gem","version":"0.2.5","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.4.24"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2mw-fvj9-vvcw","versionConstraint":">=0,<=0.4.23 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"net-imap","version":"0.2.5"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-q2mw-fvj9-vvcw","fix":{"state":"fixed","versions":["0.4.24"],"available":[{"date":"2026-05-05","kind":"first-observed","version":"0.4.24"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42245","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42245","date":"2026-10-08","epss":0.007,"percentile":0.51706}],"risk":0.1855,"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw","https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96","https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda","https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819","https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/releases/tag/v0.6.4","https://nvd.nist.gov/vuln/detail/CVE-2026-42245","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-42245.yml"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2mw-fvj9-vvcw","description":"net-imap has quadratic complexity when reading response literals"},"relatedVulnerabilities":[{"id":"CVE-2026-42245","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42245","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42245","date":"2026-10-08","epss":0.007,"percentile":0.51706}],"urls":["https://github.com/ruby/net-imap/commit/6091f7d6b1f3514cafbfe39c76f2b5d73de3ca96","https://github.com/ruby/net-imap/commit/88d95231fc8afef11c1f074453f7d75b68c9dfda","https://github.com/ruby/net-imap/commit/de685f91a4a4cc75eb80da898c2bf8af08d34819","https://github.com/ruby/net-imap/releases/tag/v0.4.24","https://github.com/ruby/net-imap/releases/tag/v0.5.14","https://github.com/ruby/net-imap/releases/tag/v0.6.4","https://github.com/ruby/net-imap/security/advisories/GHSA-q2mw-fvj9-vvcw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42245","description":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4."}]},{"artifact":{"id":"14cfe0f375d6d1af","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.2?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.2","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wx95-c6cv-8532","versionConstraint":">=1.5.1,<1.19.1 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-wx95-c6cv-8532","fix":{"state":"fixed","versions":["1.19.1"],"available":[{"date":"2026-03-04","kind":"first-observed","version":"1.19.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79772","cwe":"CWE-252","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-79772","date":"2026-10-08","epss":0.00342,"percentile":0.25585}],"risk":0.17612999999999998,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532","https://nvd.nist.gov/vuln/detail/CVE-2026-79772","https://www.vulncheck.com/advisories/nokogiri-before-unchecked-return-value-canonicalize"],"severity":"Medium","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wx95-c6cv-8532","description":"Nokogiri does not check the return value from xmlC14NExecute"},"relatedVulnerabilities":[{"id":"CVE-2026-79772","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79772","cwe":"CWE-252","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-79772","date":"2026-10-08","epss":0.00342,"percentile":0.25585}],"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532","https://www.vulncheck.com/advisories/nokogiri-before-unchecked-return-value-canonicalize"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79772","description":"Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d89ef5f93ba22208","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"dbc0224a08459408","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"8213e07a58a8ec78","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.7?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"16e6be2ba255a19b","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"cd80a8862611238d","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.3:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.3","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"a40eddf63a9cb985","cpes":["cpe:2.3:a:json_project:json:2.12.2:*:*:*:*:ruby:*:*","cpe:2.3:a:ruby-lang:json:2.12.2:*:*:*:*:ruby:*:*"],"name":"json","purl":"pkg:gem/json@2.12.2","type":"gem","version":"2.12.2","language":"ruby","licenses":["Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/json-2.12.2-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/json-2.12.2-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.19.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x2f5-4prf-w687","versionConstraint":">=2.9.0,<2.19.9 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"json","version":"2.12.2"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-x2f5-4prf-w687","fix":{"state":"fixed","versions":["2.19.9"],"available":[{"date":"2026-07-24","kind":"first-observed","version":"2.19.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54696","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54696","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54696","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54696","date":"2026-10-08","epss":0.00382,"percentile":0.30075}],"risk":0.12797,"urls":["https://github.com/ruby/json/security/advisories/GHSA-x2f5-4prf-w687","https://nvd.nist.gov/vuln/detail/CVE-2026-54696","https://github.com/ruby/json/commit/996bac686d64e4e3aaeae03b14a7f9ee9695ebdb","https://github.com/ruby/json/releases/tag/v2.19.9","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2026-54696.yml"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x2f5-4prf-w687","description":"Ruby json: JSON generator heap buffer overflow when streaming to an IO"},"relatedVulnerabilities":[{"id":"CVE-2026-54696","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54696","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54696","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54696","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54696","date":"2026-10-08","epss":0.00382,"percentile":0.30075}],"urls":["https://github.com/ruby/json/releases/tag/v2.19.9","https://github.com/ruby/json/security/advisories/GHSA-x2f5-4prf-w687"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54696","description":"Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an\nattacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"b904e73d5a852202","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"c3e10f285acbebe8","cpes":["cpe:2.3:a:ruby-lang:net\\:\\:imap:0.2.5:*:*:*:*:ruby:*:*"],"name":"net-imap","purl":"pkg:gem/net-imap@0.2.5","type":"gem","version":"0.2.5","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.5.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-46q3-7gv7-qmgg","versionConstraint":"<=0.5.14 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"net-imap","version":"0.2.5"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-46q3-7gv7-qmgg","fix":{"state":"fixed","versions":["0.5.15"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"0.5.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47242","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47242","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47242","date":"2026-10-08","epss":0.00184,"percentile":0.07268}],"risk":0.09936,"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-46q3-7gv7-qmgg","https://github.com/ruby/net-imap/releases/tag/v0.6.4.1","https://nvd.nist.gov/vuln/detail/CVE-2026-47242","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-47242.yml","https://www.cve.org/CVERecord?id=CVE-2026-47242"],"severity":"Medium","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-46q3-7gv7-qmgg","description":"Net::IMAP: Command Injection via ID command argument"},"relatedVulnerabilities":[{"id":"CVE-2026-47242","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47242","cwe":"CWE-77","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47242","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47242","date":"2026-10-08","epss":0.00184,"percentile":0.07268}],"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-46q3-7gv7-qmgg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47242","description":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15."}]},{"artifact":{"id":"c3e10f285acbebe8","cpes":["cpe:2.3:a:ruby-lang:net\\:\\:imap:0.2.5:*:*:*:*:ruby:*:*"],"name":"net-imap","purl":"pkg:gem/net-imap@0.2.5","type":"gem","version":"0.2.5","language":"ruby","licenses":["BSD-2-Clause","Ruby"],"locations":[{"path":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/specifications/net-imap-0.2.5.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.5.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4fp-cxrr-mj66","versionConstraint":"<=0.5.14 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"net-imap","version":"0.2.5"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-c4fp-cxrr-mj66","fix":{"state":"fixed","versions":["0.5.15"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"0.5.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47241","cwe":"CWE-162","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47241","cwe":"CWE-182","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47241","cwe":"CWE-186","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47241","date":"2026-10-08","epss":0.00382,"percentile":0.30092}],"risk":0.09741,"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-c4fp-cxrr-mj66","https://github.com/ruby/net-imap/releases/tag/v0.6.4.1","https://nvd.nist.gov/vuln/detail/CVE-2026-47241","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-47241.yml","https://www.cve.org/CVERecord?id=CVE-2026-47241"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4fp-cxrr-mj66","description":"Net::IMAP: Denial of Service via incomplete raw argument validation"},"relatedVulnerabilities":[{"id":"CVE-2026-47241","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47241","cwe":"CWE-162","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47241","cwe":"CWE-182","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-47241","cwe":"CWE-186","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47241","date":"2026-10-08","epss":0.00382,"percentile":0.30092}],"urls":["https://github.com/ruby/net-imap/security/advisories/GHSA-c4fp-cxrr-mj66"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47241","description":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another command is sent (from another thread). That other command will not return until the connection is closed. This vulnerability is fixed in 0.6.5 and 0.5.15."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"b904e73d5a852202","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-integration-kafka-11.8.12-java/vendor/jar-dependencies/at/yawk/lz4/lz4-java/1.10.1/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mcr4-qmvw-px4g","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mcr4-qmvw-px4g","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"risk":0.061419999999999995,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","https://nvd.nist.gov/vuln/detail/CVE-2026-106451","https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mcr4-qmvw-px4g","description":"yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user"},"relatedVulnerabilities":[{"id":"CVE-2026-106451","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"urls":["https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"17317631a09f6a3f","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"c37cad8d5a3a6548","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:55169beb4ed0a75f442d493ccb19083a6ab899f52aec1d3e171430d660ace6cb","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:d81fb2a7c6ee3be05fdefaa7fd223be219c1ab172083ec1b994c3ecda33ac0a8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5prr-v3j2-97mh","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-5prr-v3j2-97mh","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5prr-v3j2-97mh"],"severity":"Medium","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5prr-v3j2-97mh","description":"Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5v8h-3h3q-446p","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-5v8h-3h3q-446p","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5v8h-3h3q-446p"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5v8h-3h3q-446p","description":"Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8678-w3jw-xfc2","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-8678-w3jw-xfc2","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.6,"impactScore":1.5,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-8678-w3jw-xfc2"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8678-w3jw-xfc2","description":"Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9cv2-cfxc-v4v2","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-9cv2-cfxc-v4v2","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-9cv2-cfxc-v4v2"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9cv2-cfxc-v4v2","description":"Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p67v-3w7g-wjg7","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-p67v-3w7g-wjg7","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-p67v-3w7g-wjg7"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p67v-3w7g-wjg7","description":"Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-phwj-rprq-35pp","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-phwj-rprq-35pp","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-phwj-rprq-35pp"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-phwj-rprq-35pp","description":"Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wfpw-mmfh-qq69","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-wfpw-mmfh-qq69","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wfpw-mmfh-qq69"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wfpw-mmfh-qq69","description":"Nokogiri: Possible Use-After-Free in XInclude Processing"},"relatedVulnerabilities":[]},{"artifact":{"id":"1f5fb98341e748d0","cpes":["cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:ruby:*:*","cpe:2.3:a:nokogiri:nokogiri:1.18.10:*:*:*:*:*:*:*"],"name":"nokogiri","purl":"pkg:gem/nokogiri@1.18.10","type":"gem","version":"1.18.10","language":"ruby","licenses":["MIT"],"locations":[{"path":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","layerID":"sha256:234eae24ff02c348f9195717a3878ef71eebdc674e2d0b64e4fb416ab395fcb9","accessPath":"/usr/share/logstash/vendor/bundle/jruby/3.1.0/specifications/nokogiri-1.18.10-java.gemspec","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.19.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjv4-x9w8-wm3h","versionConstraint":"<1.19.4 (gem)"},"matcher":"ruby-gem-matcher","searchedBy":{"package":{"name":"nokogiri","version":"1.18.10"},"language":"ruby","namespace":"github:language:ruby"}}],"vulnerability":{"id":"GHSA-wjv4-x9w8-wm3h","fix":{"state":"fixed","versions":["1.19.4"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.19.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wjv4-x9w8-wm3h"],"severity":"Low","namespace":"github:language:ruby","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjv4-x9w8-wm3h","description":"Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type"},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-09T22:46:26.385Z","grype_db_version":"2026-10-09T06:32:32.000Z"}