{"grype_matches":[{"artifact":{"id":"5a201eb2fb7c65e6","cpes":["cpe:2.3:a:ldb:ldb:4.21.9-r1:*:*:*:*:*:*:*"],"name":"ldb","purl":"pkg:apk/alpine/ldb@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libldb.so.2"},{"path":"/usr/lib/libldb.so.2.10.0"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libldb-key-value-private-samba.so"},{"path":"/usr/lib/samba/libldb-mdb-int-private-samba.so"},{"path":"/usr/lib/samba/libldb-tdb-err-map-private-samba.so"},{"path":"/usr/lib/samba/libldb-tdb-int-private-samba.so"},{"path":"/usr/lib/samba/ldb"},{"path":"/usr/lib/samba/ldb/asq.so"},{"path":"/usr/lib/samba/ldb/ldb.so"},{"path":"/usr/lib/samba/ldb/mdb.so"},{"path":"/usr/lib/samba/ldb/paged_searches.so"},{"path":"/usr/lib/samba/ldb/rdn_name.so"},{"path":"/usr/lib/samba/ldb/sample.so"},{"path":"/usr/lib/samba/ldb/server_sort.so"},{"path":"/usr/lib/samba/ldb/skel.so"},{"path":"/usr/lib/samba/ldb/tdb.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"006dcac63d8d64f8","cpes":["cpe:2.3:a:libauth-samba:libauth-samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth-samba:libauth_samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth_samba:libauth-samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth_samba:libauth_samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth:libauth-samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth:libauth_samba:4.21.9-r1:*:*:*:*:*:*:*"],"name":"libauth-samba","purl":"pkg:apk/alpine/libauth-samba@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libauth-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"660f734f76819afb","cpes":["cpe:2.3:a:libsmbclient:libsmbclient:4.21.9-r1:*:*:*:*:*:*:*"],"name":"libsmbclient","purl":"pkg:apk/alpine/libsmbclient@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libsmbclient.so.0"},{"path":"/usr/lib/libsmbclient.so.0.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"48f3307fda3a9362","cpes":["cpe:2.3:a:libwbclient:libwbclient:4.21.9-r1:*:*:*:*:*:*:*"],"name":"libwbclient","purl":"pkg:apk/alpine/libwbclient@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libwbclient.so.0"},{"path":"/usr/lib/libwbclient.so.0.16"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"955698e1264bc95e","cpes":["cpe:2.3:a:samba-client:samba-client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client:samba_client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba-client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba_client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_client:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-client","purl":"pkg:apk/alpine/samba-client@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/cifsdd"},{"path":"/usr/bin/dbwrap_tool"},{"path":"/usr/bin/dumpmscat"},{"path":"/usr/bin/mdsearch"},{"path":"/usr/bin/mvxattr"},{"path":"/usr/bin/nmblookup"},{"path":"/usr/bin/oLschema2ldif"},{"path":"/usr/bin/regdiff"},{"path":"/usr/bin/regpatch"},{"path":"/usr/bin/regshell"},{"path":"/usr/bin/regtree"},{"path":"/usr/bin/rpcclient"},{"path":"/usr/bin/samba-regedit"},{"path":"/usr/bin/sharesec"},{"path":"/usr/bin/smbcacls"},{"path":"/usr/bin/smbclient"},{"path":"/usr/bin/smbcquotas"},{"path":"/usr/bin/smbget"},{"path":"/usr/bin/smbprint"},{"path":"/usr/bin/smbspool"},{"path":"/usr/bin/smbtar"},{"path":"/usr/bin/smbtree"},{"path":"/usr/bin/wspsearch"},{"path":"/usr/lib"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/smbspool_krb5_wrapper"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"648eef2fe123fe73","cpes":["cpe:2.3:a:samba-client-libs:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client-libs:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client_libs:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client_libs:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-client-libs","purl":"pkg:apk/alpine/samba-client-libs@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libdcerpc.so.0"},{"path":"/usr/lib/libdcerpc.so.0.0.1"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libad-claims-private-samba.so"},{"path":"/usr/lib/samba/libauthn-policy-util-private-samba.so"},{"path":"/usr/lib/samba/libcli-ldap-private-samba.so"},{"path":"/usr/lib/samba/libcmdline-contexts-private-samba.so"},{"path":"/usr/lib/samba/libdsdb-garbage-collect-tombstones-private-samba.so"},{"path":"/usr/lib/samba/libdsdb-module-private-samba.so"},{"path":"/usr/lib/samba/libgpo-private-samba.so"},{"path":"/usr/lib/samba/libhttp-private-samba.so"},{"path":"/usr/lib/samba/libmscat-private-samba.so"},{"path":"/usr/lib/samba/libnetif-private-samba.so"},{"path":"/usr/lib/samba/libprinter-driver-private-samba.so"},{"path":"/usr/lib/samba/libregistry-private-samba.so"},{"path":"/usr/lib/samba/libsmbclient-raw-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb0901359d608ac4","cpes":["cpe:2.3:a:samba-common:samba-common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-common:samba_common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_common:samba-common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_common:samba_common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_common:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-common","purl":"pkg:apk/alpine/samba-common@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/samba"},{"path":"/etc/samba"},{"path":"/etc/samba/smb.conf"},{"path":"/var"},{"path":"/var/cache"},{"path":"/var/cache/samba"},{"path":"/var/lib"},{"path":"/var/lib/samba"},{"path":"/var/lib/samba/bind-dns"},{"path":"/var/lib/samba/private"},{"path":"/var/lib/samba/sysvol"},{"path":"/var/log"},{"path":"/var/log/samba"},{"path":"/var/run"},{"path":"/var/run/samba"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"68eae407467765ba","cpes":["cpe:2.3:a:samba-libs:samba-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-libs:samba_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_libs:samba-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_libs:samba_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_libs:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-libs","purl":"pkg:apk/alpine/samba-libs@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libdcerpc-binding.so.0"},{"path":"/usr/lib/libdcerpc-binding.so.0.0.1"},{"path":"/usr/lib/libndr-krb5pac.so.0"},{"path":"/usr/lib/libndr-krb5pac.so.0.0.1"},{"path":"/usr/lib/libndr-nbt.so.0"},{"path":"/usr/lib/libndr-nbt.so.0.0.1"},{"path":"/usr/lib/libndr-standard.so.0"},{"path":"/usr/lib/libndr-standard.so.0.0.1"},{"path":"/usr/lib/libndr.so.5"},{"path":"/usr/lib/libndr.so.5.0.0"},{"path":"/usr/lib/libsamba-credentials.so.1"},{"path":"/usr/lib/libsamba-credentials.so.1.0.0"},{"path":"/usr/lib/libsamba-errors.so.1"},{"path":"/usr/lib/libsamba-errors.so.1.0.0"},{"path":"/usr/lib/libsamba-hostconfig.so.0"},{"path":"/usr/lib/libsamba-hostconfig.so.0.0.1"},{"path":"/usr/lib/libsamba-passdb.so.0"},{"path":"/usr/lib/libsamba-passdb.so.0.29.0"},{"path":"/usr/lib/libsamdb.so.0"},{"path":"/usr/lib/libsamdb.so.0.0.1"},{"path":"/usr/lib/libsmbconf.so.0"},{"path":"/usr/lib/libsmbconf.so.0.0.1"},{"path":"/usr/lib/libsmbldap.so.2"},{"path":"/usr/lib/libsmbldap.so.2.1.0"},{"path":"/usr/lib/libtevent-util.so.0"},{"path":"/usr/lib/libtevent-util.so.0.0.1"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libCHARSET3-private-samba.so"},{"path":"/usr/lib/samba/libMESSAGING-SEND-private-samba.so"},{"path":"/usr/lib/samba/libMESSAGING-private-samba.so"},{"path":"/usr/lib/samba/libaddns-private-samba.so"},{"path":"/usr/lib/samba/libads-private-samba.so"},{"path":"/usr/lib/samba/libasn1-private-samba.so"},{"path":"/usr/lib/samba/libasn1util-private-samba.so"},{"path":"/usr/lib/samba/libauthkrb5-private-samba.so"},{"path":"/usr/lib/samba/libcli-cldap-private-samba.so"},{"path":"/usr/lib/samba/libcli-ldap-common-private-samba.so"},{"path":"/usr/lib/samba/libcli-nbt-private-samba.so"},{"path":"/usr/lib/samba/libcli-smb-common-private-samba.so"},{"path":"/usr/lib/samba/libcli-spoolss-private-samba.so"},{"path":"/usr/lib/samba/libcliauth-private-samba.so"},{"path":"/usr/lib/samba/libclidns-private-samba.so"},{"path":"/usr/lib/samba/libcluster-private-samba.so"},{"path":"/usr/lib/samba/libcmdline-private-samba.so"},{"path":"/usr/lib/samba/libcmocka-private-samba.so"},{"path":"/usr/lib/samba/libcommon-auth-private-samba.so"},{"path":"/usr/lib/samba/libdbwrap-private-samba.so"},{"path":"/usr/lib/samba/libdcerpc-pkt-auth-private-samba.so"},{"path":"/usr/lib/samba/libdcerpc-samba-private-samba.so"},{"path":"/usr/lib/samba/libevents-private-samba.so"},{"path":"/usr/lib/samba/libflag-mapping-private-samba.so"},{"path":"/usr/lib/samba/libgensec-private-samba.so"},{"path":"/usr/lib/samba/libgse-private-samba.so"},{"path":"/usr/lib/samba/libgssapi-private-samba.so"},{"path":"/usr/lib/samba/libhcrypto-private-samba.so"},{"path":"/usr/lib/samba/libheimbase-private-samba.so"},{"path":"/usr/lib/samba/libheimntlm-private-samba.so"},{"path":"/usr/lib/samba/libhx509-private-samba.so"},{"path":"/usr/lib/samba/libinterfaces-private-samba.so"},{"path":"/usr/lib/samba/libkrb5-private-samba.so"},{"path":"/usr/lib/samba/libkrb5samba-private-samba.so"},{"path":"/usr/lib/samba/libldbsamba-private-samba.so"},{"path":"/usr/lib/samba/liblibcli-lsa3-private-samba.so"},{"path":"/usr/lib/samba/liblibcli-netlogon3-private-samba.so"},{"path":"/usr/lib/samba/liblibsmb-private-samba.so"},{"path":"/usr/lib/samba/libmessages-dgm-private-samba.so"},{"path":"/usr/lib/samba/libmessages-util-private-samba.so"},{"path":"/usr/lib/samba/libmsghdr-private-samba.so"},{"path":"/usr/lib/samba/libmsrpc3-private-samba.so"},{"path":"/usr/lib/samba/libndr-samba-private-samba.so"},{"path":"/usr/lib/samba/libndr-samba4-private-samba.so"},{"path":"/usr/lib/samba/libnpa-tstream-private-samba.so"},{"path":"/usr/lib/samba/libroken-private-samba.so"},{"path":"/usr/lib/samba/libsamba-cluster-support-private-samba.so"},{"path":"/usr/lib/samba/libsamba-modules-private-samba.so"},{"path":"/usr/lib/samba/libsamba-security-private-samba.so"},{"path":"/usr/lib/samba/libsamba-sockets-private-samba.so"},{"path":"/usr/lib/samba/libsamba3-util-private-samba.so"},{"path":"/usr/lib/samba/libsamdb-common-private-samba.so"},{"path":"/usr/lib/samba/libsecrets3-private-samba.so"},{"path":"/usr/lib/samba/libserver-id-db-private-samba.so"},{"path":"/usr/lib/samba/libserver-role-private-samba.so"},{"path":"/usr/lib/samba/libsmb-transport-private-samba.so"},{"path":"/usr/lib/samba/libsmbd-shim-private-samba.so"},{"path":"/usr/lib/samba/libtalloc-report-printf-private-samba.so"},{"path":"/usr/lib/samba/libtalloc-report-private-samba.so"},{"path":"/usr/lib/samba/libtdb-wrap-private-samba.so"},{"path":"/usr/lib/samba/libutil-crypt-private-samba.so"},{"path":"/usr/lib/samba/libutil-reg-private-samba.so"},{"path":"/usr/lib/samba/libutil-setid-private-samba.so"},{"path":"/usr/lib/samba/libutil-tdb-private-samba.so"},{"path":"/usr/lib/samba/libwind-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"c41f3e12e1487be8","cpes":["cpe:2.3:a:samba-util-libs:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-util-libs:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util_libs:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util_libs:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-util:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-util:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-util-libs","purl":"pkg:apk/alpine/samba-util-libs@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libsamba-util.so.0"},{"path":"/usr/lib/libsamba-util.so.0.0.1"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libcom-err-private-samba.so"},{"path":"/usr/lib/samba/libgenrand-private-samba.so"},{"path":"/usr/lib/samba/libiov-buf-private-samba.so"},{"path":"/usr/lib/samba/libreplace-private-samba.so"},{"path":"/usr/lib/samba/libsamba-debug-private-samba.so"},{"path":"/usr/lib/samba/libsocket-blocking-private-samba.so"},{"path":"/usr/lib/samba/libstable-sort-private-samba.so"},{"path":"/usr/lib/samba/libsys-rw-private-samba.so"},{"path":"/usr/lib/samba/libtime-basic-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2011-2411","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2011-2411","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","metrics":{"baseScore":9,"impactScore":10.1,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2011-2411","date":"2026-10-08","epss":0.0599,"percentile":0.93131}],"risk":4.94175,"urls":["http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03008543"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-2411","description":"Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors."},"relatedVulnerabilities":[]},{"artifact":{"id":"a9135707992c3cc1","cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:apk/alpine/imagemagick@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ImageMagick-7"},{"path":"/etc/ImageMagick-7/colors.xml"},{"path":"/etc/ImageMagick-7/delegates.xml"},{"path":"/etc/ImageMagick-7/log.xml"},{"path":"/etc/ImageMagick-7/mime.xml"},{"path":"/etc/ImageMagick-7/policy.xml"},{"path":"/etc/ImageMagick-7/quantization-table.xml"},{"path":"/etc/ImageMagick-7/thresholds.xml"},{"path":"/etc/ImageMagick-7/type-apple.xml"},{"path":"/etc/ImageMagick-7/type-dejavu.xml"},{"path":"/etc/ImageMagick-7/type-ghostscript.xml"},{"path":"/etc/ImageMagick-7/type-urw-base35-type1.xml"},{"path":"/etc/ImageMagick-7/type-urw-base35.xml"},{"path":"/etc/ImageMagick-7/type-windows.xml"},{"path":"/etc/ImageMagick-7/type.xml"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/animate"},{"path":"/usr/bin/compare"},{"path":"/usr/bin/composite"},{"path":"/usr/bin/conjure"},{"path":"/usr/bin/convert"},{"path":"/usr/bin/display"},{"path":"/usr/bin/identify"},{"path":"/usr/bin/import"},{"path":"/usr/bin/magick"},{"path":"/usr/bin/magick-script"},{"path":"/usr/bin/mogrify"},{"path":"/usr/bin/montage"},{"path":"/usr/bin/stream"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/config-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/config-Q16HDRI/configure.xml"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/aai.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/aai.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/art.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/art.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ashlar.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ashlar.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/avs.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/avs.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bayer.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bayer.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bgr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bgr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bmp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bmp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/braille.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/braille.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cals.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cals.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/caption.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/caption.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cin.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cin.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cip.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cip.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/clip.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/clip.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cmyk.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cmyk.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cube.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cube.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cut.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cut.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dcm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dcm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dds.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dds.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/debug.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/debug.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dib.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dib.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dot.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dot.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dpx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dpx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ept.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ept.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/farbfeld.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/farbfeld.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fax.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fax.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fits.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fits.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fl32.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fl32.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ftxt.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ftxt.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gif.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gif.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gradient.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gradient.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gray.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gray.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hald.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hald.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hdr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hdr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/histogram.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/histogram.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hrz.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hrz.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/html.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/html.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/icon.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/icon.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/info.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/info.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/inline.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/inline.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ipl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ipl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jnx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jnx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/json.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/json.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/kernel.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/kernel.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/label.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/label.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mac.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mac.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/magick.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/magick.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/map.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/map.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mask.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mask.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mat.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mat.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/matte.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/matte.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/meta.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/meta.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/miff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/miff.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mono.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mono.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpc.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpc.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/msl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/msl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mtv.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mtv.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mvg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mvg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/null.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/null.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ora.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ora.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/otb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/otb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/palm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/palm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pattern.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pattern.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pes.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pes.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pgx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pgx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pict.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pict.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pix.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pix.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/plasma.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/plasma.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/png.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/png.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pnm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pnm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps2.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps2.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps3.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps3.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/psd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/psd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pwp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pwp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/qoi.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/qoi.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/raw.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/raw.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rla.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rla.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rle.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rle.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/scr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/scr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sct.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sct.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sf3.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sf3.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sfw.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sfw.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sgi.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sgi.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sixel.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sixel.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/stegano.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/stegano.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/strimg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/strimg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sun.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sun.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tga.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tga.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/thumbnail.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/thumbnail.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tile.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tile.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim2.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim2.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ttf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ttf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/txt.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/txt.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uil.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uil.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/url.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/url.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uyvy.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uyvy.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vicar.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vicar.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vid.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vid.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/video.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/video.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/viff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/viff.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vips.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vips.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wbmp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wbmp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wpg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wpg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/x.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/x.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xbm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xbm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xc.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xc.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xcf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xcf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xpm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xpm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xps.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xps.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xwd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xwd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yaml.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yaml.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ycbcr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ycbcr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yuv.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yuv.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters/analyze.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters/analyze.so"},{"path":"/usr/share"},{"path":"/usr/share/ImageMagick-7"},{"path":"/usr/share/ImageMagick-7/english.xml"},{"path":"/usr/share/ImageMagick-7/francais.xml"},{"path":"/usr/share/ImageMagick-7/locale.xml"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"e996d573ace7ac8a","cpes":["cpe:2.3:a:imagemagick-heic:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-heic:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_heic:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_heic:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-heic","purl":"pkg:apk/alpine/imagemagick-heic@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/heic.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/heic.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"3f08e1664f1c4c2f","cpes":["cpe:2.3:a:imagemagick-jpeg:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-jpeg:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jpeg:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jpeg:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-jpeg","purl":"pkg:apk/alpine/imagemagick-jpeg@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jpeg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jpeg.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"9125e14a7cc7e8f7","cpes":["cpe:2.3:a:imagemagick-jxl:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-jxl:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jxl:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jxl:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-jxl","purl":"pkg:apk/alpine/imagemagick-jxl@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jxl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jxl.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"5ed371762b203874","cpes":["cpe:2.3:a:imagemagick-libs:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-libs:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_libs:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_libs:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-libs","purl":"pkg:apk/alpine/imagemagick-libs@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libMagickCore-7.Q16HDRI.so.10"},{"path":"/usr/lib/libMagickCore-7.Q16HDRI.so.10.0.2"},{"path":"/usr/lib/libMagickWand-7.Q16HDRI.so.10"},{"path":"/usr/lib/libMagickWand-7.Q16HDRI.so.10.0.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"97b1ee64ba6c099a","cpes":["cpe:2.3:a:imagemagick-openexr:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-openexr:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_openexr:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_openexr:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-openexr","purl":"pkg:apk/alpine/imagemagick-openexr@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/exr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/exr.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"de9bfac078cb5a13","cpes":["cpe:2.3:a:imagemagick-pango:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-pango:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pango:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pango:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-pango","purl":"pkg:apk/alpine/imagemagick-pango@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pango.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pango.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"3efef3ca58e1c0df","cpes":["cpe:2.3:a:imagemagick-pdf:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-pdf:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pdf:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pdf:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-pdf","purl":"pkg:apk/alpine/imagemagick-pdf@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"21b4338ce53ca7e2","cpes":["cpe:2.3:a:imagemagick-svg:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-svg:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_svg:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_svg:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-svg","purl":"pkg:apk/alpine/imagemagick-svg@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/svg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/svg.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"92fbe1b8696410f5","cpes":["cpe:2.3:a:imagemagick-tiff:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-tiff:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_tiff:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_tiff:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-tiff","purl":"pkg:apk/alpine/imagemagick-tiff@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tiff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tiff.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"5330c43d61b42fca","cpes":["cpe:2.3:a:imagemagick-webp:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-webp:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_webp:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_webp:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-webp","purl":"pkg:apk/alpine/imagemagick-webp@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/webp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/webp.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2014-9826","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2014-9826","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-9826","cwe":"CWE-388","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-9826","date":"2026-10-08","epss":0.03738,"percentile":0.89557}],"risk":3.298785,"urls":["http://www.openwall.com/lists/oss-security/2014/12/24/1","http://www.openwall.com/lists/oss-security/2016/06/02/13","https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=69490f5cffbda612e15a2985699455bb0b45e276","https://bugzilla.redhat.com/show_bug.cgi?id=1343482"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-9826","description":"ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files."},"relatedVulnerabilities":[]},{"artifact":{"id":"a9135707992c3cc1","cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:apk/alpine/imagemagick@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ImageMagick-7"},{"path":"/etc/ImageMagick-7/colors.xml"},{"path":"/etc/ImageMagick-7/delegates.xml"},{"path":"/etc/ImageMagick-7/log.xml"},{"path":"/etc/ImageMagick-7/mime.xml"},{"path":"/etc/ImageMagick-7/policy.xml"},{"path":"/etc/ImageMagick-7/quantization-table.xml"},{"path":"/etc/ImageMagick-7/thresholds.xml"},{"path":"/etc/ImageMagick-7/type-apple.xml"},{"path":"/etc/ImageMagick-7/type-dejavu.xml"},{"path":"/etc/ImageMagick-7/type-ghostscript.xml"},{"path":"/etc/ImageMagick-7/type-urw-base35-type1.xml"},{"path":"/etc/ImageMagick-7/type-urw-base35.xml"},{"path":"/etc/ImageMagick-7/type-windows.xml"},{"path":"/etc/ImageMagick-7/type.xml"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/animate"},{"path":"/usr/bin/compare"},{"path":"/usr/bin/composite"},{"path":"/usr/bin/conjure"},{"path":"/usr/bin/convert"},{"path":"/usr/bin/display"},{"path":"/usr/bin/identify"},{"path":"/usr/bin/import"},{"path":"/usr/bin/magick"},{"path":"/usr/bin/magick-script"},{"path":"/usr/bin/mogrify"},{"path":"/usr/bin/montage"},{"path":"/usr/bin/stream"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/config-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/config-Q16HDRI/configure.xml"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/aai.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/aai.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/art.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/art.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ashlar.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ashlar.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/avs.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/avs.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bayer.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bayer.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bgr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bgr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bmp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bmp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/braille.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/braille.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cals.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cals.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/caption.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/caption.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cin.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cin.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cip.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cip.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/clip.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/clip.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cmyk.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cmyk.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cube.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cube.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cut.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cut.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dcm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dcm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dds.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dds.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/debug.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/debug.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dib.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dib.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dot.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dot.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dpx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dpx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ept.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ept.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/farbfeld.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/farbfeld.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fax.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fax.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fits.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fits.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fl32.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fl32.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ftxt.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ftxt.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gif.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gif.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gradient.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gradient.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gray.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gray.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hald.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hald.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hdr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hdr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/histogram.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/histogram.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hrz.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hrz.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/html.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/html.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/icon.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/icon.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/info.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/info.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/inline.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/inline.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ipl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ipl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jnx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jnx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/json.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/json.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/kernel.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/kernel.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/label.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/label.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mac.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mac.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/magick.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/magick.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/map.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/map.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mask.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mask.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mat.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mat.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/matte.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/matte.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/meta.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/meta.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/miff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/miff.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mono.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mono.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpc.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpc.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/msl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/msl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mtv.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mtv.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mvg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mvg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/null.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/null.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ora.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ora.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/otb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/otb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/palm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/palm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pattern.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pattern.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pes.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pes.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pgx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pgx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pict.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pict.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pix.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pix.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/plasma.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/plasma.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/png.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/png.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pnm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pnm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps2.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps2.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps3.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps3.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/psd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/psd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pwp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pwp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/qoi.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/qoi.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/raw.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/raw.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rla.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rla.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rle.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rle.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/scr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/scr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sct.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sct.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sf3.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sf3.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sfw.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sfw.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sgi.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sgi.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sixel.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sixel.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/stegano.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/stegano.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/strimg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/strimg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sun.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sun.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tga.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tga.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/thumbnail.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/thumbnail.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tile.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tile.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim2.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim2.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ttf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ttf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/txt.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/txt.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uil.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uil.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/url.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/url.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uyvy.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uyvy.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vicar.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vicar.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vid.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vid.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/video.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/video.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/viff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/viff.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vips.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vips.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wbmp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wbmp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wpg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wpg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/x.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/x.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xbm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xbm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xc.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xc.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xcf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xcf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xpm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xpm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xps.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xps.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xwd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xwd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yaml.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yaml.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ycbcr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ycbcr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yuv.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yuv.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters/analyze.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters/analyze.so"},{"path":"/usr/share"},{"path":"/usr/share/ImageMagick-7"},{"path":"/usr/share/ImageMagick-7/english.xml"},{"path":"/usr/share/ImageMagick-7/francais.xml"},{"path":"/usr/share/ImageMagick-7/locale.xml"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"e996d573ace7ac8a","cpes":["cpe:2.3:a:imagemagick-heic:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-heic:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_heic:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_heic:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-heic","purl":"pkg:apk/alpine/imagemagick-heic@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/heic.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/heic.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"3f08e1664f1c4c2f","cpes":["cpe:2.3:a:imagemagick-jpeg:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-jpeg:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jpeg:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jpeg:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-jpeg","purl":"pkg:apk/alpine/imagemagick-jpeg@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jpeg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jpeg.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"9125e14a7cc7e8f7","cpes":["cpe:2.3:a:imagemagick-jxl:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-jxl:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jxl:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jxl:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-jxl","purl":"pkg:apk/alpine/imagemagick-jxl@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jxl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jxl.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"5ed371762b203874","cpes":["cpe:2.3:a:imagemagick-libs:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-libs:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_libs:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_libs:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-libs","purl":"pkg:apk/alpine/imagemagick-libs@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libMagickCore-7.Q16HDRI.so.10"},{"path":"/usr/lib/libMagickCore-7.Q16HDRI.so.10.0.2"},{"path":"/usr/lib/libMagickWand-7.Q16HDRI.so.10"},{"path":"/usr/lib/libMagickWand-7.Q16HDRI.so.10.0.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"97b1ee64ba6c099a","cpes":["cpe:2.3:a:imagemagick-openexr:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-openexr:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_openexr:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_openexr:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-openexr","purl":"pkg:apk/alpine/imagemagick-openexr@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/exr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/exr.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"de9bfac078cb5a13","cpes":["cpe:2.3:a:imagemagick-pango:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-pango:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pango:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pango:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-pango","purl":"pkg:apk/alpine/imagemagick-pango@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pango.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pango.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"3efef3ca58e1c0df","cpes":["cpe:2.3:a:imagemagick-pdf:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-pdf:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pdf:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pdf:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-pdf","purl":"pkg:apk/alpine/imagemagick-pdf@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"21b4338ce53ca7e2","cpes":["cpe:2.3:a:imagemagick-svg:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-svg:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_svg:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_svg:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-svg","purl":"pkg:apk/alpine/imagemagick-svg@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/svg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/svg.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"92fbe1b8696410f5","cpes":["cpe:2.3:a:imagemagick-tiff:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-tiff:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_tiff:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_tiff:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-tiff","purl":"pkg:apk/alpine/imagemagick-tiff@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tiff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tiff.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"5330c43d61b42fca","cpes":["cpe:2.3:a:imagemagick-webp:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-webp:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_webp:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_webp:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-webp","purl":"pkg:apk/alpine/imagemagick-webp@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/webp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/webp.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-7538","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-7538","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-7538","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-7538","date":"2026-10-08","epss":0.03371,"percentile":0.88423}],"risk":1.7529199999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/09/22/2","http://www.securityfocus.com/bid/93131","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1556273","https://bugzilla.redhat.com/show_bug.cgi?id=1378775","https://github.com/ImageMagick/ImageMagick/commit/82e2049862a8b8a999e160734ad64fb6cc3b145f","https://github.com/ImageMagick/ImageMagick/issues/148"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-7538","description":"coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"4619ae3aa570ed9c","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-52356","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1:*:*:*:*:*:*:*"],"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-52356","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52356","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-52356","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-52356","date":"2026-10-08","epss":0.02187,"percentile":0.81857}],"risk":1.64025,"urls":["https://access.redhat.com/errata/RHSA-2024:5079","https://access.redhat.com/errata/RHSA-2025:20801","https://access.redhat.com/errata/RHSA-2025:21994","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:5958","https://access.redhat.com/errata/RHSA-2026:7081","https://access.redhat.com/errata/RHSA-2026:7304","https://access.redhat.com/errata/RHSA-2026:7335","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/security/cve/CVE-2023-52356","https://bugzilla.redhat.com/show_bug.cgi?id=2251344","https://gitlab.com/libtiff/libtiff/-/issues/622","https://gitlab.com/libtiff/libtiff/-/merge_requests/546","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.debian.org/debian-lts-announce/2024/03/msg00011.html","https://lists.debian.org/debian-lts-announce/2025/01/msg00019.html","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52356","description":"A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"a9135707992c3cc1","cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:apk/alpine/imagemagick@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ImageMagick-7"},{"path":"/etc/ImageMagick-7/colors.xml"},{"path":"/etc/ImageMagick-7/delegates.xml"},{"path":"/etc/ImageMagick-7/log.xml"},{"path":"/etc/ImageMagick-7/mime.xml"},{"path":"/etc/ImageMagick-7/policy.xml"},{"path":"/etc/ImageMagick-7/quantization-table.xml"},{"path":"/etc/ImageMagick-7/thresholds.xml"},{"path":"/etc/ImageMagick-7/type-apple.xml"},{"path":"/etc/ImageMagick-7/type-dejavu.xml"},{"path":"/etc/ImageMagick-7/type-ghostscript.xml"},{"path":"/etc/ImageMagick-7/type-urw-base35-type1.xml"},{"path":"/etc/ImageMagick-7/type-urw-base35.xml"},{"path":"/etc/ImageMagick-7/type-windows.xml"},{"path":"/etc/ImageMagick-7/type.xml"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/animate"},{"path":"/usr/bin/compare"},{"path":"/usr/bin/composite"},{"path":"/usr/bin/conjure"},{"path":"/usr/bin/convert"},{"path":"/usr/bin/display"},{"path":"/usr/bin/identify"},{"path":"/usr/bin/import"},{"path":"/usr/bin/magick"},{"path":"/usr/bin/magick-script"},{"path":"/usr/bin/mogrify"},{"path":"/usr/bin/montage"},{"path":"/usr/bin/stream"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/config-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/config-Q16HDRI/configure.xml"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/aai.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/aai.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/art.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/art.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ashlar.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ashlar.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/avs.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/avs.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bayer.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bayer.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bgr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bgr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bmp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/bmp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/braille.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/braille.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cals.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cals.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/caption.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/caption.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cin.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cin.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cip.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cip.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/clip.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/clip.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cmyk.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cmyk.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cube.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cube.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cut.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/cut.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dcm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dcm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dds.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dds.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/debug.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/debug.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dib.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dib.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dot.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dot.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dpx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/dpx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ept.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ept.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/farbfeld.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/farbfeld.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fax.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fax.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fits.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fits.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fl32.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/fl32.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ftxt.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ftxt.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gif.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gif.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gradient.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gradient.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gray.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/gray.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hald.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hald.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hdr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hdr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/histogram.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/histogram.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hrz.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/hrz.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/html.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/html.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/icon.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/icon.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/info.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/info.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/inline.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/inline.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ipl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ipl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jnx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jnx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/json.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/json.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/kernel.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/kernel.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/label.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/label.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mac.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mac.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/magick.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/magick.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/map.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/map.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mask.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mask.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mat.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mat.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/matte.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/matte.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/meta.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/meta.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/miff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/miff.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mono.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mono.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpc.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpc.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mpr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/msl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/msl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mtv.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mtv.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mvg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/mvg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/null.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/null.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ora.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ora.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/otb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/otb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/palm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/palm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pattern.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pattern.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcl.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pcx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pes.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pes.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pgx.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pgx.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pict.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pict.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pix.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pix.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/plasma.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/plasma.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/png.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/png.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pnm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pnm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps2.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps2.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps3.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps3.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/psd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/psd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pwp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pwp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/qoi.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/qoi.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/raw.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/raw.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgb.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgb.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rgf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rla.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rla.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rle.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/rle.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/scr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/scr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sct.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sct.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sf3.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sf3.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sfw.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sfw.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sgi.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sgi.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sixel.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sixel.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/stegano.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/stegano.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/strimg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/strimg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sun.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/sun.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tga.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tga.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/thumbnail.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/thumbnail.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tile.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tile.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim2.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tim2.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ttf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ttf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/txt.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/txt.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uil.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uil.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/url.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/url.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uyvy.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/uyvy.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vicar.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vicar.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vid.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vid.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/video.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/video.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/viff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/viff.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vips.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/vips.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wbmp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wbmp.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wpg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/wpg.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/x.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/x.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xbm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xbm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xc.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xc.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xcf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xcf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xpm.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xpm.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xps.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xps.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xwd.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/xwd.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yaml.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yaml.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ycbcr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ycbcr.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yuv.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/yuv.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters/analyze.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/filters/analyze.so"},{"path":"/usr/share"},{"path":"/usr/share/ImageMagick-7"},{"path":"/usr/share/ImageMagick-7/english.xml"},{"path":"/usr/share/ImageMagick-7/francais.xml"},{"path":"/usr/share/ImageMagick-7/locale.xml"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"e996d573ace7ac8a","cpes":["cpe:2.3:a:imagemagick-heic:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-heic:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_heic:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_heic:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-heic:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_heic:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-heic","purl":"pkg:apk/alpine/imagemagick-heic@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/heic.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/heic.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"3f08e1664f1c4c2f","cpes":["cpe:2.3:a:imagemagick-jpeg:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-jpeg:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jpeg:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jpeg:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-jpeg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_jpeg:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-jpeg","purl":"pkg:apk/alpine/imagemagick-jpeg@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jpeg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jpeg.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"9125e14a7cc7e8f7","cpes":["cpe:2.3:a:imagemagick-jxl:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-jxl:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jxl:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_jxl:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-jxl:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_jxl:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-jxl","purl":"pkg:apk/alpine/imagemagick-jxl@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jxl.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/jxl.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"5ed371762b203874","cpes":["cpe:2.3:a:imagemagick-libs:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-libs:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_libs:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_libs:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-libs:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_libs:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-libs","purl":"pkg:apk/alpine/imagemagick-libs@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libMagickCore-7.Q16HDRI.so.10"},{"path":"/usr/lib/libMagickCore-7.Q16HDRI.so.10.0.2"},{"path":"/usr/lib/libMagickWand-7.Q16HDRI.so.10"},{"path":"/usr/lib/libMagickWand-7.Q16HDRI.so.10.0.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"97b1ee64ba6c099a","cpes":["cpe:2.3:a:imagemagick-openexr:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-openexr:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_openexr:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_openexr:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-openexr:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_openexr:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-openexr","purl":"pkg:apk/alpine/imagemagick-openexr@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/exr.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/exr.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"de9bfac078cb5a13","cpes":["cpe:2.3:a:imagemagick-pango:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-pango:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pango:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pango:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-pango:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_pango:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-pango","purl":"pkg:apk/alpine/imagemagick-pango@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pango.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pango.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"3efef3ca58e1c0df","cpes":["cpe:2.3:a:imagemagick-pdf:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-pdf:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pdf:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_pdf:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-pdf:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_pdf:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-pdf","purl":"pkg:apk/alpine/imagemagick-pdf@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdf.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/pdf.so"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/ps.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"21b4338ce53ca7e2","cpes":["cpe:2.3:a:imagemagick-svg:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-svg:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_svg:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_svg:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-svg:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_svg:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-svg","purl":"pkg:apk/alpine/imagemagick-svg@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/svg.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/svg.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"92fbe1b8696410f5","cpes":["cpe:2.3:a:imagemagick-tiff:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-tiff:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_tiff:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_tiff:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-tiff:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_tiff:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-tiff","purl":"pkg:apk/alpine/imagemagick-tiff@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tiff.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/tiff.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"5330c43d61b42fca","cpes":["cpe:2.3:a:imagemagick-webp:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-webp:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_webp:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_webp:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-webp:7.1.2.15-r0:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_webp:7.1.2.15-r0:*:*:*:*:*:*:*"],"name":"imagemagick-webp","purl":"pkg:apk/alpine/imagemagick-webp@7.1.2.15-r0?arch=x86_64&distro=alpine-3.22.6&upstream=imagemagick","type":"apk","version":"7.1.2.15-r0","language":"","licenses":["ImageMagick"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/ImageMagick-7.1.2"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/webp.la"},{"path":"/usr/lib/ImageMagick-7.1.2/modules-Q16HDRI/coders/webp.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"imagemagick"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2017-5506","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:imagemagick:imagemagick:7.1.2.15:*:*:*:*:*:*:*"],"package":{"name":"imagemagick","version":"7.1.2.15-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2017-5506","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-5506","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-5506","date":"2026-10-08","epss":0.02071,"percentile":0.80852}],"risk":1.53254,"urls":["http://www.debian.org/security/2017/dsa-3799","http://www.openwall.com/lists/oss-security/2017/01/16/6","http://www.openwall.com/lists/oss-security/2017/01/17/5","http://www.securityfocus.com/bid/95753","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383","https://github.com/ImageMagick/ImageMagick/commit/9a069e0f2e027ec5138f998023cf9cb62c04889f","https://github.com/ImageMagick/ImageMagick/issues/354","https://security.gentoo.org/glsa/201702-09"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-5506","description":"Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file."},"relatedVulnerabilities":[]},{"artifact":{"id":"9a224549c18cd43b","cpes":["cpe:2.3:a:libarchive:libarchive:3.8.3-r0:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:apk/alpine/libarchive@3.8.3-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.8.3-r0","language":"","licenses":["AND","BSD-2-Clause","BSD-3-Clause","Public-Domain"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libarchive.so.13"},{"path":"/usr/lib/libarchive.so.13.8.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libarchive"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-5121","versionConstraint":"< 3.8.7 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libarchive:libarchive:3.8.3:*:*:*:*:*:*:*"],"package":{"name":"libarchive","version":"3.8.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-5121","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5121","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-5121","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-5121","date":"2026-10-08","epss":0.0143,"percentile":0.72215}],"risk":1.261975,"urls":["https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10097","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:12071","https://access.redhat.com/errata/RHSA-2026:12274","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14773","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:15087","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:17596","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:20040","https://access.redhat.com/errata/RHSA-2026:21690","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:8510","https://access.redhat.com/errata/RHSA-2026:8517","https://access.redhat.com/errata/RHSA-2026:8521","https://access.redhat.com/errata/RHSA-2026:8534","https://access.redhat.com/errata/RHSA-2026:8864","https://access.redhat.com/errata/RHSA-2026:8866","https://access.redhat.com/errata/RHSA-2026:8867","https://access.redhat.com/errata/RHSA-2026:8873","https://access.redhat.com/errata/RHSA-2026:8908","https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/errata/RHSA-2026:9026","https://access.redhat.com/errata/RHSA-2026:9592","https://access.redhat.com/errata/RHSA-2026:9832","https://access.redhat.com/security/cve/CVE-2026-5121","https://bugzilla.redhat.com/show_bug.cgi?id=2452945","https://github.com/advisories/GHSA-2vwv-vqpv-v8vc","https://github.com/libarchive/libarchive/pull/2934","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5121","description":"A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6722","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6722","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Red","metrics":{"baseScore":9.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6722","cwe":"CWE-416","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-6722","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6722","date":"2026-10-08","epss":0.01295,"percentile":0.69462}],"risk":1.1655,"urls":["https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5","https://access.redhat.com/errata/RHSA-2026:22142","https://access.redhat.com/errata/RHSA-2026:22143","https://access.redhat.com/errata/RHSA-2026:22305","https://access.redhat.com/errata/RHSA-2026:22649","https://access.redhat.com/errata/RHSA-2026:23388","https://access.redhat.com/errata/RHSA-2026:33449","https://access.redhat.com/errata/RHSA-2026:34354","https://access.redhat.com/security/cve/CVE-2026-6722","https://bugzilla.redhat.com/show_bug.cgi?id=2468560","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6722.json"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6722","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"4619ae3aa570ed9c","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6277","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1:*:*:*:*:*:*:*"],"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6277","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6277","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6277","date":"2026-10-08","epss":0.0181,"percentile":0.77958}],"risk":1.04075,"urls":["https://access.redhat.com/security/cve/CVE-2023-6277","https://bugzilla.redhat.com/show_bug.cgi?id=2251311","https://gitlab.com/libtiff/libtiff/-/issues/614","https://gitlab.com/libtiff/libtiff/-/merge_requests/545","http://seclists.org/fulldisclosure/2024/Jul/16","http://seclists.org/fulldisclosure/2024/Jul/17","http://seclists.org/fulldisclosure/2024/Jul/18","http://seclists.org/fulldisclosure/2024/Jul/19","http://seclists.org/fulldisclosure/2024/Jul/20","http://seclists.org/fulldisclosure/2024/Jul/21","http://seclists.org/fulldisclosure/2024/Jul/22","http://seclists.org/fulldisclosure/2024/Jul/23","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJIN6DTSL3VODZUGWEUXLEL5DR53EZMV/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7ZGN2MZXJ6E57W3L4YBM3ZPAU3T7T5C/","https://security.netapp.com/advisory/ntap-20240119-0002/","https://support.apple.com/kb/HT214116","https://support.apple.com/kb/HT214117","https://support.apple.com/kb/HT214118","https://support.apple.com/kb/HT214119","https://support.apple.com/kb/HT214120","https://support.apple.com/kb/HT214122","https://support.apple.com/kb/HT214123","https://support.apple.com/kb/HT214124"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6277","description":"An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58016","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.8589450000000001,"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8461","versionConstraint":"< 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8461","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"reefs@jfrog.com"},{"cve":"CVE-2026-8461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8461","date":"2026-10-08","epss":0.01033,"percentile":0.6269}],"risk":0.8418950000000002,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159","https://access.redhat.com/errata/RHSA-2026:43711","https://access.redhat.com/security/cve/CVE-2026-8461","https://bugzilla.redhat.com/show_bug.cgi?id=2490308","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8461","description":"An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution.\n\n This vulnerability is associated with the file libavcodec/magicyuv.C.\n\n\n\nThis issue affects FFmpeg before version 8.1.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3731","versionConstraint":"<= 0.11.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3731","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"risk":0.8205,"urls":["https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60","https://vuldb.com/?ctiid.349709","https://vuldb.com/?id.349709","https://vuldb.com/?submit.767120","https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz","https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3731","description":"A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component."},"relatedVulnerabilities":[]},{"artifact":{"id":"9a224549c18cd43b","cpes":["cpe:2.3:a:libarchive:libarchive:3.8.3-r0:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:apk/alpine/libarchive@3.8.3-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.8.3-r0","language":"","licenses":["AND","BSD-2-Clause","BSD-3-Clause","Public-Domain"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libarchive.so.13"},{"path":"/usr/lib/libarchive.so.13.8.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libarchive"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-4424","versionConstraint":"< 3.8.7 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libarchive:libarchive:3.8.3:*:*:*:*:*:*:*"],"package":{"name":"libarchive","version":"3.8.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-4424","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4424","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4424","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4424","date":"2026-10-08","epss":0.01073,"percentile":0.63877}],"risk":0.8047499999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10097","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:12071","https://access.redhat.com/errata/RHSA-2026:12274","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14773","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:15087","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:17596","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:20040","https://access.redhat.com/errata/RHSA-2026:21690","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:8492","https://access.redhat.com/errata/RHSA-2026:8510","https://access.redhat.com/errata/RHSA-2026:8517","https://access.redhat.com/errata/RHSA-2026:8521","https://access.redhat.com/errata/RHSA-2026:8534","https://access.redhat.com/errata/RHSA-2026:8864","https://access.redhat.com/errata/RHSA-2026:8865","https://access.redhat.com/errata/RHSA-2026:8866","https://access.redhat.com/errata/RHSA-2026:8867","https://access.redhat.com/errata/RHSA-2026:8873","https://access.redhat.com/errata/RHSA-2026:8908","https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/errata/RHSA-2026:9026","https://access.redhat.com/errata/RHSA-2026:9592","https://access.redhat.com/errata/RHSA-2026:9832","https://access.redhat.com/security/cve/CVE-2026-4424","https://bugzilla.redhat.com/show_bug.cgi?id=2449006","https://github.com/libarchive/libarchive/pull/2898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4424.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4424","description":"A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3805","versionConstraint":">= 8.13.0, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3805","date":"2026-10-08","epss":0.00988,"percentile":0.61304}],"risk":0.741,"urls":["https://curl.se/docs/CVE-2026-3805.html","https://curl.se/docs/CVE-2026-3805.json","https://hackerone.com/reports/3591944","http://www.openwall.com/lists/oss-security/2026/03/11/4"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3805","description":"When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7262","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7262","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Amber","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7262","cwe":"CWE-476","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-7262","cwe":"CWE-476","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-7262","date":"2026-10-08","epss":0.01047,"percentile":0.63129}],"risk":0.70498,"urls":["https://github.com/php/php-src/security/advisories/GHSA-hmxp-6pc4-f3vv","https://access.redhat.com/errata/RHSA-2026:22142","https://access.redhat.com/errata/RHSA-2026:22143","https://access.redhat.com/errata/RHSA-2026:22305","https://access.redhat.com/errata/RHSA-2026:22649","https://access.redhat.com/errata/RHSA-2026:23388","https://access.redhat.com/errata/RHSA-2026:33449","https://access.redhat.com/errata/RHSA-2026:34354","https://access.redhat.com/security/cve/CVE-2026-7262","https://bugzilla.redhat.com/show_bug.cgi?id=2468565","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7262.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7262","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-19931","versionConstraint":">= 7.64.1, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14087","versionConstraint":"< 2.86.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14087","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14087","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14087","date":"2026-10-08","epss":0.00826,"percentile":0.56148}],"risk":0.6897099999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:15953","https://access.redhat.com/errata/RHSA-2026:15969","https://access.redhat.com/errata/RHSA-2026:15971","https://access.redhat.com/errata/RHSA-2026:19148","https://access.redhat.com/errata/RHSA-2026:19361","https://access.redhat.com/errata/RHSA-2026:19452","https://access.redhat.com/errata/RHSA-2026:19457","https://access.redhat.com/errata/RHSA-2026:19459","https://access.redhat.com/errata/RHSA-2026:19460","https://access.redhat.com/errata/RHSA-2026:19523","https://access.redhat.com/errata/RHSA-2026:19524","https://access.redhat.com/errata/RHSA-2026:19565","https://access.redhat.com/errata/RHSA-2026:19566","https://access.redhat.com/errata/RHSA-2026:19567","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:22634","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2025-14087","https://bugzilla.redhat.com/show_bug.cgi?id=2419093","https://gitlab.gnome.org/GNOME/glib/-/issues/3834"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14087","description":"A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80231","versionConstraint":">= 7.71.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80231","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80231","date":"2026-10-08","epss":0.00898,"percentile":0.58384}],"risk":0.6735,"urls":["https://curl.se/docs/CVE-2026-80231.html","https://curl.se/docs/CVE-2026-80231.json","https://hackerone.com/reports/3969368"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80231","description":"A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup\nfor a given hostname even when using a different Native CA Store setting\n(`CURLSSLOPT_NATIVE_CA`) than when the connection was created."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63292","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-63292","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"risk":0.657,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63292"},"relatedVulnerabilities":[{"id":"CVE-2026-63292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-11856","versionConstraint":">= 7.10.6, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58015","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.6446799999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[]},{"artifact":{"id":"1da2bc278c806801","cpes":["cpe:2.3:a:flock:flock:2.41.6-r1:*:*:*:*:*:*:*"],"name":"flock","purl":"pkg:apk/alpine/flock@2.41.6-r1?arch=x86_64&distro=alpine-3.22.6&upstream=util-linux","type":"apk","version":"2.41.6-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/flock"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:flock:flock:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2010-1236","versionConstraint":"< 3.0.0.4112 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:flock:flock:2.41.6:*:*:*:*:*:*:*"],"package":{"name":"flock","version":"2.41.6-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2010-1236","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-1236","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-1236","date":"2026-10-08","epss":0.01365,"percentile":0.70976}],"risk":0.634725,"urls":["http://code.google.com/p/chromium/issues/detail?id=37383","http://codereview.chromium.org/858001","http://flock.com/security/","http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html","http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html","http://secunia.com/advisories/43068","http://src.chromium.org/viewvc/chrome?view=rev&revision=41244","http://www.vupen.com/english/advisories/2011/0212","https://bugs.webkit.org/show_bug.cgi?id=35948","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14067"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-1236","description":"The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstrated by a \\x00javascript:alert sequence."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58010","versionConstraint":"< 2.86.5||= 2.88.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6333524999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58012","versionConstraint":"< 2.86.5||= 2.88.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6333524999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58013","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.6333524999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66040","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66040","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66040","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66040","date":"2026-10-08","epss":0.00776,"percentile":0.54427}],"risk":0.6311466666666667,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-via-png-apng-exif-encoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66040","description":"FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7568","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7568","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Amber","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7568","cwe":"CWE-125","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-7568","cwe":"CWE-190","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-7568","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-7568","date":"2026-10-08","epss":0.00839,"percentile":0.56541}],"risk":0.61247,"urls":["https://github.com/php/php-src/security/advisories/GHSA-96wq-48vp-hh57","https://access.redhat.com/errata/RHSA-2026:22142","https://access.redhat.com/errata/RHSA-2026:22143","https://access.redhat.com/errata/RHSA-2026:22305","https://access.redhat.com/errata/RHSA-2026:22649","https://access.redhat.com/errata/RHSA-2026:23388","https://access.redhat.com/errata/RHSA-2026:33449","https://access.redhat.com/errata/RHSA-2026:34354","https://access.redhat.com/security/cve/CVE-2026-7568","https://bugzilla.redhat.com/show_bug.cgi?id=2468566","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7568.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7568","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8924","versionConstraint":">= 7.46.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58011","versionConstraint":"< 2.86.5||= 2.88.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.5916,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64834","versionConstraint":">= 0.6.3, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64834","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64834","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64834","date":"2026-10-08","epss":0.00727,"percentile":0.52717}],"risk":0.56706,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663","https://www.vulncheck.com/advisories/ffmpeg-infinite-loop-dos-via-rtp-asf-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64834","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57941","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-57941","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"risk":0.5640000000000001,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-57941"},"relatedVulnerabilities":[{"id":"CVE-2026-57941","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-10536","versionConstraint":">= 7.88.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58014","versionConstraint":"< 2.88.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.5577449999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9079","versionConstraint":">= 8.8.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"risk":0.54896,"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[]},{"artifact":{"id":"45a682fc3031e4cd","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r0:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r0:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.7.19-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67215","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67215","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67215","cwe":"CWE-674","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67215","date":"2026-10-08","epss":0.007,"percentile":0.51693}],"risk":0.546,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L253-L261","https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L906-L940","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-json-patch-copy-add-uncontrolled-recursion-stack-exhaustion"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67215","description":"cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30999","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30999","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30999","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30999","date":"2026-10-08","epss":0.00728,"percentile":0.52758}],"risk":0.5459999999999999,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30999-Memory-Leak-e0d88ac53e2e42c1b5ef9aa3497e27b6","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c","https://www.ffmpeg.org/download.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999","description":"A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"5a201eb2fb7c65e6","cpes":["cpe:2.3:a:ldb:ldb:4.21.9-r1:*:*:*:*:*:*:*"],"name":"ldb","purl":"pkg:apk/alpine/ldb@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libldb.so.2"},{"path":"/usr/lib/libldb.so.2.10.0"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libldb-key-value-private-samba.so"},{"path":"/usr/lib/samba/libldb-mdb-int-private-samba.so"},{"path":"/usr/lib/samba/libldb-tdb-err-map-private-samba.so"},{"path":"/usr/lib/samba/libldb-tdb-int-private-samba.so"},{"path":"/usr/lib/samba/ldb"},{"path":"/usr/lib/samba/ldb/asq.so"},{"path":"/usr/lib/samba/ldb/ldb.so"},{"path":"/usr/lib/samba/ldb/mdb.so"},{"path":"/usr/lib/samba/ldb/paged_searches.so"},{"path":"/usr/lib/samba/ldb/rdn_name.so"},{"path":"/usr/lib/samba/ldb/sample.so"},{"path":"/usr/lib/samba/ldb/server_sort.so"},{"path":"/usr/lib/samba/ldb/skel.so"},{"path":"/usr/lib/samba/ldb/tdb.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"006dcac63d8d64f8","cpes":["cpe:2.3:a:libauth-samba:libauth-samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth-samba:libauth_samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth_samba:libauth-samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth_samba:libauth_samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth:libauth-samba:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:libauth:libauth_samba:4.21.9-r1:*:*:*:*:*:*:*"],"name":"libauth-samba","purl":"pkg:apk/alpine/libauth-samba@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libauth-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"660f734f76819afb","cpes":["cpe:2.3:a:libsmbclient:libsmbclient:4.21.9-r1:*:*:*:*:*:*:*"],"name":"libsmbclient","purl":"pkg:apk/alpine/libsmbclient@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libsmbclient.so.0"},{"path":"/usr/lib/libsmbclient.so.0.8.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"48f3307fda3a9362","cpes":["cpe:2.3:a:libwbclient:libwbclient:4.21.9-r1:*:*:*:*:*:*:*"],"name":"libwbclient","purl":"pkg:apk/alpine/libwbclient@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libwbclient.so.0"},{"path":"/usr/lib/libwbclient.so.0.16"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"955698e1264bc95e","cpes":["cpe:2.3:a:samba-client:samba-client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client:samba_client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba-client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba_client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-client:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_client:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-client","purl":"pkg:apk/alpine/samba-client@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/cifsdd"},{"path":"/usr/bin/dbwrap_tool"},{"path":"/usr/bin/dumpmscat"},{"path":"/usr/bin/mdsearch"},{"path":"/usr/bin/mvxattr"},{"path":"/usr/bin/nmblookup"},{"path":"/usr/bin/oLschema2ldif"},{"path":"/usr/bin/regdiff"},{"path":"/usr/bin/regpatch"},{"path":"/usr/bin/regshell"},{"path":"/usr/bin/regtree"},{"path":"/usr/bin/rpcclient"},{"path":"/usr/bin/samba-regedit"},{"path":"/usr/bin/sharesec"},{"path":"/usr/bin/smbcacls"},{"path":"/usr/bin/smbclient"},{"path":"/usr/bin/smbcquotas"},{"path":"/usr/bin/smbget"},{"path":"/usr/bin/smbprint"},{"path":"/usr/bin/smbspool"},{"path":"/usr/bin/smbtar"},{"path":"/usr/bin/smbtree"},{"path":"/usr/bin/wspsearch"},{"path":"/usr/lib"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/smbspool_krb5_wrapper"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"648eef2fe123fe73","cpes":["cpe:2.3:a:samba-client-libs:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client-libs:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client_libs:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client_libs:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-client:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_client:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-client-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_client_libs:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-client-libs","purl":"pkg:apk/alpine/samba-client-libs@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libdcerpc.so.0"},{"path":"/usr/lib/libdcerpc.so.0.0.1"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libad-claims-private-samba.so"},{"path":"/usr/lib/samba/libauthn-policy-util-private-samba.so"},{"path":"/usr/lib/samba/libcli-ldap-private-samba.so"},{"path":"/usr/lib/samba/libcmdline-contexts-private-samba.so"},{"path":"/usr/lib/samba/libdsdb-garbage-collect-tombstones-private-samba.so"},{"path":"/usr/lib/samba/libdsdb-module-private-samba.so"},{"path":"/usr/lib/samba/libgpo-private-samba.so"},{"path":"/usr/lib/samba/libhttp-private-samba.so"},{"path":"/usr/lib/samba/libmscat-private-samba.so"},{"path":"/usr/lib/samba/libnetif-private-samba.so"},{"path":"/usr/lib/samba/libprinter-driver-private-samba.so"},{"path":"/usr/lib/samba/libregistry-private-samba.so"},{"path":"/usr/lib/samba/libsmbclient-raw-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb0901359d608ac4","cpes":["cpe:2.3:a:samba-common:samba-common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-common:samba_common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_common:samba-common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_common:samba_common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-common:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_common:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-common","purl":"pkg:apk/alpine/samba-common@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/samba"},{"path":"/etc/samba"},{"path":"/etc/samba/smb.conf"},{"path":"/var"},{"path":"/var/cache"},{"path":"/var/cache/samba"},{"path":"/var/lib"},{"path":"/var/lib/samba"},{"path":"/var/lib/samba/bind-dns"},{"path":"/var/lib/samba/private"},{"path":"/var/lib/samba/sysvol"},{"path":"/var/log"},{"path":"/var/log/samba"},{"path":"/var/run"},{"path":"/var/run/samba"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"68eae407467765ba","cpes":["cpe:2.3:a:samba-libs:samba-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-libs:samba_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_libs:samba-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_libs:samba_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_libs:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-libs","purl":"pkg:apk/alpine/samba-libs@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libdcerpc-binding.so.0"},{"path":"/usr/lib/libdcerpc-binding.so.0.0.1"},{"path":"/usr/lib/libndr-krb5pac.so.0"},{"path":"/usr/lib/libndr-krb5pac.so.0.0.1"},{"path":"/usr/lib/libndr-nbt.so.0"},{"path":"/usr/lib/libndr-nbt.so.0.0.1"},{"path":"/usr/lib/libndr-standard.so.0"},{"path":"/usr/lib/libndr-standard.so.0.0.1"},{"path":"/usr/lib/libndr.so.5"},{"path":"/usr/lib/libndr.so.5.0.0"},{"path":"/usr/lib/libsamba-credentials.so.1"},{"path":"/usr/lib/libsamba-credentials.so.1.0.0"},{"path":"/usr/lib/libsamba-errors.so.1"},{"path":"/usr/lib/libsamba-errors.so.1.0.0"},{"path":"/usr/lib/libsamba-hostconfig.so.0"},{"path":"/usr/lib/libsamba-hostconfig.so.0.0.1"},{"path":"/usr/lib/libsamba-passdb.so.0"},{"path":"/usr/lib/libsamba-passdb.so.0.29.0"},{"path":"/usr/lib/libsamdb.so.0"},{"path":"/usr/lib/libsamdb.so.0.0.1"},{"path":"/usr/lib/libsmbconf.so.0"},{"path":"/usr/lib/libsmbconf.so.0.0.1"},{"path":"/usr/lib/libsmbldap.so.2"},{"path":"/usr/lib/libsmbldap.so.2.1.0"},{"path":"/usr/lib/libtevent-util.so.0"},{"path":"/usr/lib/libtevent-util.so.0.0.1"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libCHARSET3-private-samba.so"},{"path":"/usr/lib/samba/libMESSAGING-SEND-private-samba.so"},{"path":"/usr/lib/samba/libMESSAGING-private-samba.so"},{"path":"/usr/lib/samba/libaddns-private-samba.so"},{"path":"/usr/lib/samba/libads-private-samba.so"},{"path":"/usr/lib/samba/libasn1-private-samba.so"},{"path":"/usr/lib/samba/libasn1util-private-samba.so"},{"path":"/usr/lib/samba/libauthkrb5-private-samba.so"},{"path":"/usr/lib/samba/libcli-cldap-private-samba.so"},{"path":"/usr/lib/samba/libcli-ldap-common-private-samba.so"},{"path":"/usr/lib/samba/libcli-nbt-private-samba.so"},{"path":"/usr/lib/samba/libcli-smb-common-private-samba.so"},{"path":"/usr/lib/samba/libcli-spoolss-private-samba.so"},{"path":"/usr/lib/samba/libcliauth-private-samba.so"},{"path":"/usr/lib/samba/libclidns-private-samba.so"},{"path":"/usr/lib/samba/libcluster-private-samba.so"},{"path":"/usr/lib/samba/libcmdline-private-samba.so"},{"path":"/usr/lib/samba/libcmocka-private-samba.so"},{"path":"/usr/lib/samba/libcommon-auth-private-samba.so"},{"path":"/usr/lib/samba/libdbwrap-private-samba.so"},{"path":"/usr/lib/samba/libdcerpc-pkt-auth-private-samba.so"},{"path":"/usr/lib/samba/libdcerpc-samba-private-samba.so"},{"path":"/usr/lib/samba/libevents-private-samba.so"},{"path":"/usr/lib/samba/libflag-mapping-private-samba.so"},{"path":"/usr/lib/samba/libgensec-private-samba.so"},{"path":"/usr/lib/samba/libgse-private-samba.so"},{"path":"/usr/lib/samba/libgssapi-private-samba.so"},{"path":"/usr/lib/samba/libhcrypto-private-samba.so"},{"path":"/usr/lib/samba/libheimbase-private-samba.so"},{"path":"/usr/lib/samba/libheimntlm-private-samba.so"},{"path":"/usr/lib/samba/libhx509-private-samba.so"},{"path":"/usr/lib/samba/libinterfaces-private-samba.so"},{"path":"/usr/lib/samba/libkrb5-private-samba.so"},{"path":"/usr/lib/samba/libkrb5samba-private-samba.so"},{"path":"/usr/lib/samba/libldbsamba-private-samba.so"},{"path":"/usr/lib/samba/liblibcli-lsa3-private-samba.so"},{"path":"/usr/lib/samba/liblibcli-netlogon3-private-samba.so"},{"path":"/usr/lib/samba/liblibsmb-private-samba.so"},{"path":"/usr/lib/samba/libmessages-dgm-private-samba.so"},{"path":"/usr/lib/samba/libmessages-util-private-samba.so"},{"path":"/usr/lib/samba/libmsghdr-private-samba.so"},{"path":"/usr/lib/samba/libmsrpc3-private-samba.so"},{"path":"/usr/lib/samba/libndr-samba-private-samba.so"},{"path":"/usr/lib/samba/libndr-samba4-private-samba.so"},{"path":"/usr/lib/samba/libnpa-tstream-private-samba.so"},{"path":"/usr/lib/samba/libroken-private-samba.so"},{"path":"/usr/lib/samba/libsamba-cluster-support-private-samba.so"},{"path":"/usr/lib/samba/libsamba-modules-private-samba.so"},{"path":"/usr/lib/samba/libsamba-security-private-samba.so"},{"path":"/usr/lib/samba/libsamba-sockets-private-samba.so"},{"path":"/usr/lib/samba/libsamba3-util-private-samba.so"},{"path":"/usr/lib/samba/libsamdb-common-private-samba.so"},{"path":"/usr/lib/samba/libsecrets3-private-samba.so"},{"path":"/usr/lib/samba/libserver-id-db-private-samba.so"},{"path":"/usr/lib/samba/libserver-role-private-samba.so"},{"path":"/usr/lib/samba/libsmb-transport-private-samba.so"},{"path":"/usr/lib/samba/libsmbd-shim-private-samba.so"},{"path":"/usr/lib/samba/libtalloc-report-printf-private-samba.so"},{"path":"/usr/lib/samba/libtalloc-report-private-samba.so"},{"path":"/usr/lib/samba/libtdb-wrap-private-samba.so"},{"path":"/usr/lib/samba/libutil-crypt-private-samba.so"},{"path":"/usr/lib/samba/libutil-reg-private-samba.so"},{"path":"/usr/lib/samba/libutil-setid-private-samba.so"},{"path":"/usr/lib/samba/libutil-tdb-private-samba.so"},{"path":"/usr/lib/samba/libwind-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"c41f3e12e1487be8","cpes":["cpe:2.3:a:samba-util-libs:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-util-libs:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util_libs:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util_libs:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-util:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba-util:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba_util:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba-util-libs:4.21.9-r1:*:*:*:*:*:*:*","cpe:2.3:a:samba:samba_util_libs:4.21.9-r1:*:*:*:*:*:*:*"],"name":"samba-util-libs","purl":"pkg:apk/alpine/samba-util-libs@4.21.9-r1?arch=x86_64&distro=alpine-3.22.6&upstream=samba","type":"apk","version":"4.21.9-r1","language":"","licenses":["GPL-3.0-or-later AND LGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libsamba-util.so.0"},{"path":"/usr/lib/libsamba-util.so.0.0.1"},{"path":"/usr/lib/samba"},{"path":"/usr/lib/samba/libcom-err-private-samba.so"},{"path":"/usr/lib/samba/libgenrand-private-samba.so"},{"path":"/usr/lib/samba/libiov-buf-private-samba.so"},{"path":"/usr/lib/samba/libreplace-private-samba.so"},{"path":"/usr/lib/samba/libsamba-debug-private-samba.so"},{"path":"/usr/lib/samba/libsocket-blocking-private-samba.so"},{"path":"/usr/lib/samba/libstable-sort-private-samba.so"},{"path":"/usr/lib/samba/libsys-rw-private-samba.so"},{"path":"/usr/lib/samba/libtime-basic-private-samba.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"samba"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-2340","versionConstraint":">= 4.1.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:samba:samba:4.21.9:*:*:*:*:*:*:*"],"package":{"name":"samba","version":"4.21.9-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-2340","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2340","cwe":"CWE-280","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-2340","date":"2026-10-08","epss":0.00939,"percentile":0.59725}],"risk":0.539925,"urls":["https://access.redhat.com/errata/RHSA-2026:22644","https://access.redhat.com/errata/RHSA-2026:22963","https://access.redhat.com/errata/RHSA-2026:25049","https://access.redhat.com/errata/RHSA-2026:25979","https://access.redhat.com/errata/RHSA-2026:28053","https://access.redhat.com/errata/RHSA-2026:28054","https://access.redhat.com/errata/RHSA-2026:28055","https://access.redhat.com/errata/RHSA-2026:28056","https://access.redhat.com/errata/RHSA-2026:28057","https://access.redhat.com/errata/RHSA-2026:29863","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65907","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/security/cve/CVE-2026-2340","https://bugzilla.redhat.com/show_bug.cgi?id=2447318","https://bugzilla.samba.org/show_bug.cgi?id=15997"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2340","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-18924","versionConstraint":">= 7.44.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56154","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-56154","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"risk":0.5282800000000001,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-56154"},"relatedVulnerabilities":[{"id":"CVE-2026-56154","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64830","versionConstraint":">= 2.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64830","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64830","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64830","date":"2026-10-08","epss":0.00646,"percentile":0.49366}],"risk":0.524875,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657","https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxer"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64830","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6104","versionConstraint":">= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6104","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Amber","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6104","cwe":"CWE-125","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-6104","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6104","date":"2026-10-08","epss":0.00601,"percentile":0.47135}],"risk":0.5068433333333333,"urls":["https://github.com/php/php-src/security/advisories/GHSA-74r9-qxhc-fx53","https://access.redhat.com/errata/RHSA-2026:22649","https://access.redhat.com/security/cve/CVE-2026-6104","https://bugzilla.redhat.com/show_bug.cgi?id=2468573","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6104.json"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6104","description":"In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-5773","versionConstraint":">= 7.40.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-5773","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.49275,"urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59797","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-59797","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"risk":0.4888,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59797"},"relatedVulnerabilities":[{"id":"CVE-2026-59797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/22"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30998","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30998","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30998","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30998","date":"2026-10-08","epss":0.00651,"percentile":0.49619}],"risk":0.48824999999999996,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30998-Resource-Leak-3265a71f9cca4dc58df4632ce8b60a50","https://ffmpeg.org/doxygen/7.0/zmqsend_8c_source.html","https://github.com/FFmpeg/FFmpeg/blob/master/tools/zmqsend.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30998","description":"An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file."},"relatedVulnerabilities":[]},{"artifact":{"id":"1da2bc278c806801","cpes":["cpe:2.3:a:flock:flock:2.41.6-r1:*:*:*:*:*:*:*"],"name":"flock","purl":"pkg:apk/alpine/flock@2.41.6-r1?arch=x86_64&distro=alpine-3.22.6&upstream=util-linux","type":"apk","version":"2.41.6-r1","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/flock"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:flock:flock:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2010-3262","versionConstraint":"<= 3.0.0.3989 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:flock:flock:2.41.6:*:*:*:*:*:*:*"],"package":{"name":"flock","version":"2.41.6-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2010-3262","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-3262","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-3262","date":"2026-10-08","epss":0.01033,"percentile":0.62718}],"risk":0.48034499999999997,"urls":["http://flock.com/security/","http://www.securityfocus.com/archive/1/513701/100/0/threaded","http://www.securityfocus.com/bid/43225","https://exchange.xforce.ibmcloud.com/vulnerabilities/61820"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-3262","description":"Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed."},"relatedVulnerabilities":[]},{"artifact":{"id":"45a682fc3031e4cd","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r0:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r0:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.7.19-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67216","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67216","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67216","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67216","date":"2026-10-08","epss":0.00645,"percentile":0.49346}],"risk":0.474075,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L3057-L3180","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-service"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67216","description":"cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7263","versionConstraint":">= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7263","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Amber","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7263","cwe":"CWE-404","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-7263","cwe":"CWE-835","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-7263","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-7263","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"risk":0.4599,"urls":["https://github.com/php/php-src/security/advisories/GHSA-4jhr-8w89-j733","https://access.redhat.com/errata/RHSA-2026:22649","https://access.redhat.com/security/cve/CVE-2026-7263","https://bugzilla.redhat.com/show_bug.cgi?id=2468572","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7263.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7263","description":"In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56449","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-56449","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"risk":0.45899999999999996,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-56449"},"relatedVulnerabilities":[{"id":"CVE-2026-56449","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/18"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48005","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-48005","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"risk":0.4545,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-48005"},"relatedVulnerabilities":[{"id":"CVE-2026-48005","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/15"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7261","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7261","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:M/U:Amber","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7261","cwe":"CWE-416","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-7261","date":"2026-10-08","epss":0.00531,"percentile":0.43087}],"risk":0.4526775,"urls":["https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7261","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8927","versionConstraint":">= 7.12.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-0966","versionConstraint":"< 0.11.4 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-0966","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0966","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0966","date":"2026-10-08","epss":0.00582,"percentile":0.46086}],"risk":0.4321349999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:18160","https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/errata/RHSA-2026:7067","https://access.redhat.com/security/cve/CVE-2026-0966","https://bugzilla.redhat.com/show_bug.cgi?id=2433121","https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0966","description":"A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80229","versionConstraint":">= 8.14.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-1594","versionConstraint":">= 3.4.0, < 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-1594","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1594","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1594","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1594","date":"2026-10-08","epss":0.00578,"percentile":0.459}],"risk":0.4183275,"urls":["https://ffmpeg.org/","https://trac.ffmpeg.org/attachment/ticket/11418/poc","https://trac.ffmpeg.org/ticket/11418#comment:3","https://vuldb.com/?ctiid.296589","https://vuldb.com/?id.296589","https://vuldb.com/?submit.496929"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594","description":"A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59843","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59843","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59843","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59843","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59843","date":"2026-10-08","epss":0.00725,"percentile":0.52664}],"risk":0.416875,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59843","https://bugzilla.redhat.com/show_bug.cgi?id=2498176"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59843","description":"A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6253","versionConstraint":">= 7.14.1, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64835","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64835","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64835","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64835","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.40299999999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64835","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8926","versionConstraint":">= 8.11.1, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"risk":0.40182000000000007,"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59851","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59851","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59851","cwe":"CWE-863","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59851","date":"2026-10-08","epss":0.00489,"percentile":0.40155}],"risk":0.39853500000000003,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/security/cve/CVE-2026-59851","https://bugzilla.redhat.com/show_bug.cgi?id=2498184"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59851","description":"A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66036","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66036","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66036","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66036","date":"2026-10-08","epss":0.00496,"percentile":0.40588}],"risk":0.3951466666666666,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filter"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66036","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-30997","versionConstraint":"<= 8.0.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-30997","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-30997","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-30997","date":"2026-10-08","epss":0.00521,"percentile":0.42419}],"risk":0.39075000000000004,"urls":["https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f","https://github.com/FFmpeg/FFmpeg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-30997","description":"An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14819","versionConstraint":">= 7.87.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14819","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-14819","date":"2026-10-08","epss":0.00756,"percentile":0.53758}],"risk":0.38934,"urls":["https://curl.se/docs/CVE-2025-14819.html","https://curl.se/docs/CVE-2025-14819.json","http://www.openwall.com/lists/oss-security/2026/01/07/5"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14819","description":"When doing TLS related transfers with reused easy or multi handles and\naltering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-91765","versionConstraint":">= 8.2.0, < 8.2.34||>= 8.3.0, < 8.3.35||>= 8.4.0, < 8.4.26||>= 8.5.0, < 8.5.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-91765","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security@php.net","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91765","cwe":"CWE-674","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-91765","date":"2026-10-08","epss":0.00516,"percentile":0.42098}],"risk":0.38699999999999996,"urls":["https://github.com/php/php-src/security/advisories/GHSA-rgrp-mwpx-f6rm"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91765","description":"cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14179","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14179","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Amber","metrics":{"baseScore":7.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14179","cwe":"CWE-89","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2025-14179","cwe":"CWE-89","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-14179","date":"2026-10-08","epss":0.00439,"percentile":0.36121}],"risk":0.3826616666666666,"urls":["https://github.com/php/php-src/security/advisories/GHSA-w476-322c-wpvm","https://access.redhat.com/security/cve/CVE-2025-14179","https://bugzilla.redhat.com/show_bug.cgi?id=2468567","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14179.json"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14179","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-17544","versionConstraint":">= 8.4.0, < 8.4.24||>= 8.5.0, < 8.5.9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-17544","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17544","cwe":"CWE-787","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-17544","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.382335,"urls":["https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17544","description":"Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9547","versionConstraint":">= 7.69.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9547","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9547","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9547","date":"2026-10-08","epss":0.00508,"percentile":0.41397}],"risk":0.37846,"urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63718","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-63718","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63718"},"relatedVulnerabilities":[{"id":"CVE-2026-63718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."}]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56153","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-56153","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"risk":0.3735,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-56153"},"relatedVulnerabilities":[{"id":"CVE-2026-56153","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59685","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-59685","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59685","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59685","date":"2026-10-08","epss":0.00498,"percentile":0.40747}],"risk":0.3735,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59685"},"relatedVulnerabilities":[{"id":"CVE-2026-59685","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59685","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59685","date":"2026-10-08","epss":0.00498,"percentile":0.40747}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/21"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59685","description":"Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9080","versionConstraint":">= 8.13.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"risk":0.36556,"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80255","versionConstraint":">= 8.14.0, <= 8.14.2||>= 8.16.0, <= 8.16.1||>= 8.20.0, < 8.20.1||>= 8.31.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63686","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-63686","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63686"},"relatedVulnerabilities":[{"id":"CVE-2026-63686","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/25"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73637","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-73637","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"risk":0.35816,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73637"},"relatedVulnerabilities":[{"id":"CVE-2026-73637","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/28"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-13608","versionConstraint":">= 7.82.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93546","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-93546","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-93546"},"relatedVulnerabilities":[{"id":"CVE-2026-93546","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/30"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."}]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63045","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-63045","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"risk":0.35400000000000004,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63045"},"relatedVulnerabilities":[{"id":"CVE-2026-63045","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46729","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-46729","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"risk":0.35100000000000003,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-46729"},"relatedVulnerabilities":[{"id":"CVE-2026-46729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66039","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66039","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66039","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66039","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66039","date":"2026-10-08","epss":0.0044,"percentile":0.362}],"risk":0.35053333333333336,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631","https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-file"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66039","description":"FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14524","versionConstraint":">= 7.33.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14524","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"risk":0.3502,"urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host."},"relatedVulnerabilities":[]},{"artifact":{"id":"20eff52535634991","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1535c225c29ad6c","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"10da0231daa08e01","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"735e7cd3fbf3ac08","cpes":["cpe:2.3:a:pixman:pixman:0.46.4-r0:*:*:*:*:*:*:*"],"name":"pixman","purl":"pkg:apk/alpine/pixman@0.46.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.46.4-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpixman-1.so.0"},{"path":"/usr/lib/libpixman-1.so.0.46.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pixman"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:pixman:pixman:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-37769","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:pixman:pixman:0.46.4:*:*:*:*:*:*:*"],"package":{"name":"pixman","version":"0.46.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-37769","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-37769","cwe":"CWE-369","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-37769","date":"2026-10-08","epss":0.00586,"percentile":0.46342}],"risk":0.33694999999999997,"urls":["https://gitlab.freedesktop.org/pixman/pixman/-/issues/76"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-37769","description":"stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14512","versionConstraint":"< 2.86.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14512","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14512","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14512","date":"2026-10-08","epss":0.00579,"percentile":0.45914}],"risk":0.33292499999999997,"urls":["https://access.redhat.com/errata/RHSA-2026:15953","https://access.redhat.com/errata/RHSA-2026:15969","https://access.redhat.com/errata/RHSA-2026:15971","https://access.redhat.com/errata/RHSA-2026:19148","https://access.redhat.com/errata/RHSA-2026:19361","https://access.redhat.com/errata/RHSA-2026:19452","https://access.redhat.com/errata/RHSA-2026:19457","https://access.redhat.com/errata/RHSA-2026:19459","https://access.redhat.com/errata/RHSA-2026:19460","https://access.redhat.com/errata/RHSA-2026:19523","https://access.redhat.com/errata/RHSA-2026:19524","https://access.redhat.com/errata/RHSA-2026:19565","https://access.redhat.com/errata/RHSA-2026:19567","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:22634","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2025-14512","https://bugzilla.redhat.com/show_bug.cgi?id=2421339","https://gitlab.gnome.org/GNOME/glib/-/issues/3845"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14512","description":"A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59844","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59844","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59844","cwe":"CWE-789","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59844","date":"2026-10-08","epss":0.00567,"percentile":0.45263}],"risk":0.32602499999999995,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59844","https://bugzilla.redhat.com/show_bug.cgi?id=2498177"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59844","description":"A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9951","versionConstraint":"< 7.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9951","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9951","cwe":"CWE-122","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-9951","date":"2026-10-08","epss":0.00443,"percentile":0.36516}],"risk":0.325605,"urls":["https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9951","description":"A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-91768","versionConstraint":">= 8.2.0, < 8.2.34||>= 8.3.0, < 8.3.35||>= 8.4.0, < 8.4.26||>= 8.5.0, < 8.5.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-91768","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security@php.net","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91768","cwe":"CWE-1023","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-91768","date":"2026-10-08","epss":0.00561,"percentile":0.44906}],"risk":0.322575,"urls":["https://github.com/php/php-src/security/advisories/GHSA-62xp-839h-2637"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91768","description":"The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint."},"relatedVulnerabilities":[]},{"artifact":{"id":"9a224549c18cd43b","cpes":["cpe:2.3:a:libarchive:libarchive:3.8.3-r0:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:apk/alpine/libarchive@3.8.3-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.8.3-r0","language":"","licenses":["AND","BSD-2-Clause","BSD-3-Clause","Public-Domain"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libarchive.so.13"},{"path":"/usr/lib/libarchive.so.13.8.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libarchive"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-4426","versionConstraint":"< 3.8.7 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libarchive:libarchive:3.8.3:*:*:*:*:*:*:*"],"package":{"name":"libarchive","version":"3.8.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-4426","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4426","cwe":"CWE-1335","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4426","date":"2026-10-08","epss":0.0056,"percentile":0.44879}],"risk":0.32199999999999995,"urls":["https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/security/cve/CVE-2026-4426","https://bugzilla.redhat.com/show_bug.cgi?id=2449010","https://github.com/libarchive/libarchive/pull/2897"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4426","description":"A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73636","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-73636","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"risk":0.32136000000000003,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73636"},"relatedVulnerabilities":[{"id":"CVE-2026-73636","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59982","versionConstraint":">= 3.1.0, < 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59982","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59982","versionConstraint":">= 3.1.0, < 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59982","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59982","versionConstraint":">= 3.1.0, < 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59982","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59982","versionConstraint":">= 3.1.0, < 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59982","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59982","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59982","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59982","date":"2026-10-08","epss":0.00423,"percentile":0.34563}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59982","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59189","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59981","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59981","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m799-ffc3-8pxc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59189","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59981","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59981","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m799-ffc3-8pxc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59189","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59981","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59981","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m799-ffc3-8pxc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59189","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59189","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59189","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59189","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59981","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59981","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59981","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59981","date":"2026-10-08","epss":0.00423,"percentile":0.34562}],"risk":0.30879,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m799-ffc3-8pxc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59981","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"20eff52535634991","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1535c225c29ad6c","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"10da0231daa08e01","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9545","versionConstraint":">= 8.11.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"risk":0.30600000000000005,"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-82208","versionConstraint":">= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0||>= 8.9.1, < 8.14.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-82208","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82208","date":"2026-10-08","epss":0.00407,"percentile":0.3292}],"risk":0.30524999999999997,"urls":["https://curl.se/docs/CVE-2026-82208.html","https://curl.se/docs/CVE-2026-82208.json","https://hackerone.com/reports/3973090"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82208","description":"With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted."},"relatedVulnerabilities":[]},{"artifact":{"id":"8e8b5517d25118d4","cpes":["cpe:2.3:a:crossbeam-channel_project:crossbeam-channel:0.5.14:*:*:*:*:rust:*:*"],"name":"crossbeam-channel","purl":"pkg:cargo/crossbeam-channel@0.5.14","type":"rust-crate","version":"0.5.14","language":"rust","licenses":[],"locations":[{"path":"/usr/lib/librav1e.so.0.7.1","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/usr/lib/librav1e.so.0.7.1","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.5.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pg9f-39pc-qf8g","versionConstraint":">=0.5.12,<0.5.15 (unknown)"},"matcher":"rust-matcher","searchedBy":{"package":{"name":"crossbeam-channel","version":"0.5.14"},"language":"rust","namespace":"github:language:rust"}}],"vulnerability":{"id":"GHSA-pg9f-39pc-qf8g","fix":{"state":"fixed","versions":["0.5.15"],"available":[{"date":"2025-04-11","kind":"first-observed","version":"0.5.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4574","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4574","date":"2026-10-08","epss":0.0054,"percentile":0.43693}],"risk":0.3051,"urls":["https://github.com/crossbeam-rs/crossbeam/pull/1187","https://rustsec.org/advisories/RUSTSEC-2025-0024.html","https://nvd.nist.gov/vuln/detail/CVE-2025-4574","https://access.redhat.com/security/cve/CVE-2025-4574","https://bugzilla.redhat.com/show_bug.cgi?id=2358890"],"severity":"Medium","namespace":"github:language:rust","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pg9f-39pc-qf8g","description":"crossbeam-channel Vulnerable to Double Free on Drop"},"relatedVulnerabilities":[{"id":"CVE-2025-4574","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4574","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4574","date":"2026-10-08","epss":0.0054,"percentile":0.43693}],"urls":["https://access.redhat.com/security/cve/CVE-2025-4574","https://bugzilla.redhat.com/show_bug.cgi?id=2358890","https://github.com/advisories/GHSA-pg9f-39pc-qf8g","https://github.com/crossbeam-rs/crossbeam/pull/1187"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4574","description":"In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7168","versionConstraint":">= 7.12.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7168","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"risk":0.304365,"urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-79768","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-79768","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"risk":0.30385,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-79768"},"relatedVulnerabilities":[{"id":"CVE-2026-79768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/29"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-49501","versionConstraint":">= 6.1, < 6.1.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-49501","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-49501","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-49501","date":"2026-10-08","epss":0.00391,"percentile":0.3105}],"risk":0.30302500000000004,"urls":["https://github.com/FFmpeg/FFmpeg","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/","https://trac.ffmpeg.org/ticket/10686","https://trac.ffmpeg.org/ticket/10686#no1","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-49501","description":"Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59186","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59186","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"risk":0.30295,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab","https://github.com/AcademySoftwareFoundation/openexr/commit/904141d3a1f86327ad1e2b93fc92ce2dd5881d34","https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59186","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59186","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"risk":0.30295,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab","https://github.com/AcademySoftwareFoundation/openexr/commit/904141d3a1f86327ad1e2b93fc92ce2dd5881d34","https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59186","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59186","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"risk":0.30295,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab","https://github.com/AcademySoftwareFoundation/openexr/commit/904141d3a1f86327ad1e2b93fc92ce2dd5881d34","https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59186","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59186","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59186","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59186","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59186","date":"2026-10-08","epss":0.00415,"percentile":0.33772}],"risk":0.30295,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab","https://github.com/AcademySoftwareFoundation/openexr/commit/904141d3a1f86327ad1e2b93fc92ce2dd5881d34","https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59186","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"20eff52535634991","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1535c225c29ad6c","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"10da0231daa08e01","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12064","versionConstraint":">= 7.81.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8932","versionConstraint":">= 7.7, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-17543","versionConstraint":">= 8.2.0, < 8.2.33||>= 8.3.0, < 8.3.33||>= 8.4.0, < 8.4.24||>= 8.5.0, < 8.5.9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-17543","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X","metrics":{"baseScore":8.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17543","cwe":"CWE-89","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-17543","date":"2026-10-08","epss":0.0033,"percentile":0.24088}],"risk":0.296175,"urls":["https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17543","description":"Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59184","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59184","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"risk":0.29492,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59184","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59184","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"risk":0.29492,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59184","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59184","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"risk":0.29492,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59184","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59184","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59184","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59184","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59184","date":"2026-10-08","epss":0.00404,"percentile":0.32498}],"risk":0.29492,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1","https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c","https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59184","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59187","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59187","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"risk":0.29346,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585","https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59187","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59187","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"risk":0.29346,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585","https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59187","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59187","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"risk":0.29346,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585","https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-59187","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59187","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59187","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59187","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59187","date":"2026-10-08","epss":0.00402,"percentile":0.32301}],"risk":0.29346,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585","https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59187","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-82209","versionConstraint":">= 7.46.0, < 8.14.2||>= 8.16.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.20.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7258","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7258","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7258","cwe":"CWE-125","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-7258","date":"2026-10-08","epss":0.00405,"percentile":0.32656}],"risk":0.29159999999999997,"urls":["https://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7258","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47360","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-47360","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.2895,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-47360"},"relatedVulnerabilities":[{"id":"CVE-2026-47360","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/14"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n   \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64833","versionConstraint":">= 0.7.1, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64833","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64833","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64833","date":"2026-10-08","epss":0.00396,"percentile":0.31662}],"risk":0.28908,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64833","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"4619ae3aa570ed9c","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.7.2-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4775","versionConstraint":"< 4.7.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"alpine:distro:alpine:3.22"}},{"fix":{"suggestedVersion":"4.7.2-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4775","versionConstraint":"< 4.7.2-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-4775","fix":{"state":"fixed","versions":["4.7.2-r0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"4.7.2-r0"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4775","date":"2026-10-08","epss":0.00375,"percentile":0.29323}],"risk":0.286875,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-4775"},"relatedVulnerabilities":[{"id":"CVE-2026-4775","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4775","date":"2026-10-08","epss":0.00375,"percentile":0.29323}],"urls":["https://access.redhat.com/errata/RHSA-2026:12265","https://access.redhat.com/errata/RHSA-2026:12271","https://access.redhat.com/errata/RHSA-2026:14929","https://access.redhat.com/errata/RHSA-2026:16055","https://access.redhat.com/errata/RHSA-2026:19150","https://access.redhat.com/errata/RHSA-2026:19363","https://access.redhat.com/errata/RHSA-2026:19585","https://access.redhat.com/errata/RHSA-2026:19586","https://access.redhat.com/errata/RHSA-2026:19604","https://access.redhat.com/errata/RHSA-2026:19608","https://access.redhat.com/errata/RHSA-2026:19609","https://access.redhat.com/errata/RHSA-2026:19657","https://access.redhat.com/errata/RHSA-2026:19659","https://access.redhat.com/errata/RHSA-2026:19702","https://access.redhat.com/errata/RHSA-2026:20583","https://access.redhat.com/errata/RHSA-2026:20585","https://access.redhat.com/errata/RHSA-2026:20591","https://access.redhat.com/errata/RHSA-2026:20592","https://access.redhat.com/errata/RHSA-2026:24992","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:25910","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:30349","https://access.redhat.com/errata/RHSA-2026:33388","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-4775","https://bugzilla.redhat.com/show_bug.cgi?id=2450768","https://lists.debian.org/debian-lts-announce/2026/04/msg00016.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4775.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4775","description":"A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15079","versionConstraint":">= 7.58.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.28325,"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."},"relatedVulnerabilities":[]},{"artifact":{"id":"d4217b86f833fe68","cpes":["cpe:2.3:a:zlib:zlib:1.3.2-r0:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.3.2-r0","language":"","licenses":["Zlib"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libz.so.1"},{"path":"/usr/lib/libz.so.1.3.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zlib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.22"}},{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"fixed","versions":["1.3.2-r1"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.3.2-r1"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59849","versionConstraint":">= 0.11.0, < 0.11.5||= 0.12.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59849","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59849","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59849","date":"2026-10-08","epss":0.00438,"percentile":0.36062}],"risk":0.28032,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/security/cve/CVE-2026-59849","https://bugzilla.redhat.com/show_bug.cgi?id=2498182"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59849","description":"A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80230","versionConstraint":">= 7.45.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6605","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6605","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6605","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2023-6605","date":"2026-10-08","epss":0.00376,"percentile":0.29428}],"risk":0.27636,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334336","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6605","description":"A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58415","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-58415","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"risk":0.274495,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-58415"},"relatedVulnerabilities":[{"id":"CVE-2026-58415","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/20"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"56358396d10e1f92","cpes":["cpe:2.3:a:OpenPrinting:cups-libs:2.4.18-r0:*:*:*:*:*:*:*","cpe:2.3:a:OpenPrinting:cups_libs:2.4.18-r0:*:*:*:*:*:*:*","cpe:2.3:a:cups-libs:cups-libs:2.4.18-r0:*:*:*:*:*:*:*","cpe:2.3:a:cups-libs:cups_libs:2.4.18-r0:*:*:*:*:*:*:*","cpe:2.3:a:cups_libs:cups-libs:2.4.18-r0:*:*:*:*:*:*:*","cpe:2.3:a:cups_libs:cups_libs:2.4.18-r0:*:*:*:*:*:*:*","cpe:2.3:a:cups:cups-libs:2.4.18-r0:*:*:*:*:*:*:*","cpe:2.3:a:cups:cups_libs:2.4.18-r0:*:*:*:*:*:*:*"],"name":"cups-libs","purl":"pkg:apk/alpine/cups-libs@2.4.18-r0?arch=x86_64&distro=alpine-3.22.6&upstream=cups","type":"apk","version":"2.4.18-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcups.so.2"},{"path":"/usr/lib/libcupsimage.so.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cups"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:cups:cups:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2018-6553","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:cups:cups:2.4.18:*:*:*:*:*:*:*"],"package":{"name":"cups","version":"2.4.18-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2018-6553","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":6.1,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":4.6,"impactScore":6.5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-6553","date":"2026-10-08","epss":0.00385,"percentile":0.30405}],"risk":0.27335,"urls":["https://lists.debian.org/debian-lts-announce/2018/07/msg00014.html","https://security.gentoo.org/glsa/201908-08","https://usn.ubuntu.com/usn/usn-3713-1","https://www.debian.org/security/2018/dsa-4243"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6553","description":"The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-64832","versionConstraint":">= 4.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-64832","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64832","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-64832","date":"2026-10-08","epss":0.00335,"percentile":0.24797}],"risk":0.27218749999999997,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664","https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64832","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3783","versionConstraint":">= 7.33.0, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3783","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-08","epss":0.00525,"percentile":0.42692}],"risk":0.27037500000000003,"urls":["https://curl.se/docs/CVE-2026-3783.html","https://curl.se/docs/CVE-2026-3783.json","https://hackerone.com/reports/3583983","http://www.openwall.com/lists/oss-security/2026/03/11/2"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3783","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3784","versionConstraint":">= 7.7, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"risk":0.26967499999999994,"urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6429","versionConstraint":">= 7.14.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6276","versionConstraint":">= 7.71.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6602","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6602","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6602","cwe":"CWE-99","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-6602","date":"2026-10-08","epss":0.00506,"percentile":0.41297}],"risk":0.26059000000000004,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334338","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602","description":"A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66038","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66038","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66038","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66038","date":"2026-10-08","epss":0.00439,"percentile":0.36186}],"risk":0.256815,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626","https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66038","description":"FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services."},"relatedVulnerabilities":[]},{"artifact":{"id":"5d09167023dfa218","cpes":["cpe:2.3:a:gnome:glib:2.84.4-r0:*:*:*:*:*:*:*","cpe:2.3:a:glib:glib:2.84.4-r0:*:*:*:*:*:*:*"],"name":"glib","purl":"pkg:apk/alpine/glib@2.84.4-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.84.4-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/gapplication"},{"path":"/usr/bin/gdbus"},{"path":"/usr/bin/gi-compile-repository"},{"path":"/usr/bin/gi-decompile-typelib"},{"path":"/usr/bin/gi-inspect-typelib"},{"path":"/usr/bin/gio"},{"path":"/usr/bin/gio-querymodules"},{"path":"/usr/bin/glib-compile-schemas"},{"path":"/usr/bin/gsettings"},{"path":"/usr/lib"},{"path":"/usr/lib/libgio-2.0.so.0"},{"path":"/usr/lib/libgio-2.0.so.0.8400.4"},{"path":"/usr/lib/libgirepository-2.0.so.0"},{"path":"/usr/lib/libgirepository-2.0.so.0.8400.4"},{"path":"/usr/lib/libglib-2.0.so.0"},{"path":"/usr/lib/libglib-2.0.so.0.8400.4"},{"path":"/usr/lib/libgmodule-2.0.so.0"},{"path":"/usr/lib/libgmodule-2.0.so.0.8400.4"},{"path":"/usr/lib/libgobject-2.0.so.0"},{"path":"/usr/lib/libgobject-2.0.so.0.8400.4"},{"path":"/usr/lib/libgthread-2.0.so.0"},{"path":"/usr/lib/libgthread-2.0.so.0.8400.4"},{"path":"/usr/lib/gio"},{"path":"/usr/lib/gio/modules"},{"path":"/usr/lib/girepository-1.0"},{"path":"/usr/lib/girepository-1.0/GIRepository-3.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLib-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GLibUnix-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GModule-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GObject-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/Gio-2.0.typelib"},{"path":"/usr/lib/girepository-1.0/GioUnix-2.0.typelib"},{"path":"/usr/libexec"},{"path":"/usr/libexec/gio-launch-desktop"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-13601","versionConstraint":"< 2.86.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnome:glib:2.84.4:*:*:*:*:*:*:*"],"package":{"name":"glib","version":"2.84.4-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-13601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.2,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13601","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-13601","date":"2026-10-08","epss":0.00322,"percentile":0.23253}],"risk":0.24472,"urls":["https://access.redhat.com/errata/RHSA-2026:0936","https://access.redhat.com/errata/RHSA-2026:0975","https://access.redhat.com/errata/RHSA-2026:0991","https://access.redhat.com/errata/RHSA-2026:1323","https://access.redhat.com/errata/RHSA-2026:1324","https://access.redhat.com/errata/RHSA-2026:1326","https://access.redhat.com/errata/RHSA-2026:1327","https://access.redhat.com/errata/RHSA-2026:1465","https://access.redhat.com/errata/RHSA-2026:1608","https://access.redhat.com/errata/RHSA-2026:1624","https://access.redhat.com/errata/RHSA-2026:1625","https://access.redhat.com/errata/RHSA-2026:1626","https://access.redhat.com/errata/RHSA-2026:1627","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:18344","https://access.redhat.com/errata/RHSA-2026:18705","https://access.redhat.com/errata/RHSA-2026:2064","https://access.redhat.com/errata/RHSA-2026:2072","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2633","https://access.redhat.com/errata/RHSA-2026:2659","https://access.redhat.com/errata/RHSA-2026:2671","https://access.redhat.com/errata/RHSA-2026:2974","https://access.redhat.com/errata/RHSA-2026:3415","https://access.redhat.com/errata/RHSA-2026:4419","https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/security/cve/CVE-2025-13601","https://bugzilla.redhat.com/show_bug.cgi?id=2416741","https://gitlab.gnome.org/GNOME/glib/-/issues/3827","https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13601","description":"A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-22919","versionConstraint":"< 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-22919","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22919","cwe":"CWE-617","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22919","date":"2026-10-08","epss":0.00422,"percentile":0.34489}],"risk":0.24264999999999998,"urls":["https://trac.ffmpeg.org/ticket/11385","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22919","description":"A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6604","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6604","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6604","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6604","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6604","date":"2026-10-08","epss":0.00469,"percentile":0.3859}],"risk":0.241535,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2334337","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604","description":"A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8286","versionConstraint":">= 7.30.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."},"relatedVulnerabilities":[]},{"artifact":{"id":"45a682fc3031e4cd","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r0:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r0:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.7.19-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-67217","versionConstraint":"<= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-67217","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67217","cwe":"CWE-696","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67217","date":"2026-10-08","epss":0.00433,"percentile":0.35564}],"risk":0.24031499999999997,"urls":["https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L887-L948","https://joshua.hu/cjson-json-parser-cve-vulnerabilities","https://www.vulncheck.com/advisories/cjson-json-patch-non-atomic-application-destroys-data-before-validation"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67217","description":"cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59847","versionConstraint":">= 0.9.0, < 0.11.5||= 0.12.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59847","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59847","cwe":"CWE-253","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59847","cwe":"CWE-1310","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59847","date":"2026-10-08","epss":0.00332,"percentile":0.24421}],"risk":0.23571999999999999,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59847","https://bugzilla.redhat.com/show_bug.cgi?id=2498180"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59847","description":"A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection."},"relatedVulnerabilities":[]},{"artifact":{"id":"223fa6c66161090f","cpes":["cpe:2.3:a:avahi-libs:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi-libs:avahi_libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi_libs:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi_libs:avahi_libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi:avahi_libs:0.8-r21:*:*:*:*:*:*:*"],"name":"avahi-libs","purl":"pkg:apk/alpine/avahi-libs@0.8-r21?arch=x86_64&distro=alpine-3.22.6&upstream=avahi","type":"apk","version":"0.8-r21","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavahi-client.so.3"},{"path":"/usr/lib/libavahi-client.so.3.2.9"},{"path":"/usr/lib/libavahi-common.so.3"},{"path":"/usr/lib/libavahi-common.so.3.5.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"avahi"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-68471","versionConstraint":"<= 0.9-rc2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:avahi:avahi:0.8:*:*:*:*:*:*:*"],"package":{"name":"avahi","version":"0.8-r21"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-68471","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"risk":0.23287499999999997,"urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59850","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59850","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59850","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59850","date":"2026-10-08","epss":0.00346,"percentile":0.26038}],"risk":0.23182000000000003,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59850","https://bugzilla.redhat.com/show_bug.cgi?id=2498183"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59850","description":"A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions."},"relatedVulnerabilities":[]},{"artifact":{"id":"89c2bb68f73416f2","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.49.2-r1:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:apk/alpine/sqlite-libs@3.49.2-r1?arch=x86_64&distro=alpine-3.22.6&upstream=sqlite","type":"apk","version":"3.49.2-r1","language":"","licenses":["blessing"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libsqlite3.so.0"},{"path":"/usr/lib/libsqlite3.so.3.49.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-11822","versionConstraint":"< 3.53.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:sqlite:sqlite:3.49.2:*:*:*:*:*:*:*"],"package":{"name":"sqlite","version":"3.49.2-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.23005499999999998,"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65703","versionConstraint":">= 2.7, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65703","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65703","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65703","date":"2026-10-08","epss":0.00292,"percentile":0.19919}],"risk":0.22849,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773","https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decoder"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65703","description":"FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"89c2bb68f73416f2","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.49.2-r1:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.49.2-r1:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:apk/alpine/sqlite-libs@3.49.2-r1?arch=x86_64&distro=alpine-3.22.6&upstream=sqlite","type":"apk","version":"3.49.2-r1","language":"","licenses":["blessing"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libsqlite3.so.0"},{"path":"/usr/lib/libsqlite3.so.3.49.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-70873","versionConstraint":"< 3.51.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:sqlite:sqlite:3.49.2:*:*:*:*:*:*:*"],"package":{"name":"sqlite","version":"3.49.2-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-70873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-70873","date":"2026-10-08","epss":0.00301,"percentile":0.20911}],"risk":0.22575,"urls":["https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054","https://sqlite.org/forum/forumpost/761eac3c82","https://sqlite.org/src/info/3d459f1fb1bd1b5e"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-70873","description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file."},"relatedVulnerabilities":[]},{"artifact":{"id":"223fa6c66161090f","cpes":["cpe:2.3:a:avahi-libs:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi-libs:avahi_libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi_libs:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi_libs:avahi_libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi:avahi_libs:0.8-r21:*:*:*:*:*:*:*"],"name":"avahi-libs","purl":"pkg:apk/alpine/avahi-libs@0.8-r21?arch=x86_64&distro=alpine-3.22.6&upstream=avahi","type":"apk","version":"0.8-r21","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavahi-client.so.3"},{"path":"/usr/lib/libavahi-client.so.3.2.9"},{"path":"/usr/lib/libavahi-common.so.3"},{"path":"/usr/lib/libavahi-common.so.3.5.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"avahi"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-68468","versionConstraint":"<= 0.9-rc2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:avahi:avahi:0.8:*:*:*:*:*:*:*"],"package":{"name":"avahi","version":"0.8-r21"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-68468","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"risk":0.2185,"urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-0964","versionConstraint":"< 0.11.4 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-0964","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0964","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0964","date":"2026-10-08","epss":0.00408,"percentile":0.33005}],"risk":0.21726,"urls":["https://access.redhat.com/errata/RHSA-2026:18160","https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/security/cve/CVE-2026-0964","https://bugzilla.redhat.com/show_bug.cgi?id=2436979","https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0964","description":"A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8458","versionConstraint":">= 7.43.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6601","versionConstraint":">= 2.0, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6601","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6601","cwe":"CWE-99","type":"Secondary","source":"patrick@puiterwijk.org"},{"cve":"CVE-2023-6601","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-6601","date":"2026-10-08","epss":0.00425,"percentile":0.34762}],"risk":0.206125,"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=2253172","https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6601","description":"A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions."},"relatedVulnerabilities":[]},{"artifact":{"id":"45a682fc3031e4cd","cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19-r0:*:*:*:*:*:*:*","cpe:2.3:a:cjson:cjson:1.7.19-r0:*:*:*:*:*:*:*"],"name":"cjson","purl":"pkg:apk/alpine/cjson@1.7.19-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.7.19-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcjson.so.1"},{"path":"/usr/lib/libcjson.so.1.7.19"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cjson"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-16554","versionConstraint":"= 1.7.19 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:DaveGamble:cjson:1.7.19:*:*:*:*:*:*:*"],"package":{"name":"cjson","version":"1.7.19-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-16554","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16554","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16554","date":"2026-10-08","epss":0.00291,"percentile":0.19897}],"risk":0.2029725,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-16554","https://github.com/DaveGamble/cJSON","http://www.openwall.com/lists/oss-security/2026/07/30/26","http://www.openwall.com/lists/oss-security/2026/07/31/4"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16554","description":"cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to remote code execution, information disclosure, or denial of service.\n\n\n\n\nBecause project creator contact attempts were unsuccessful, the vulnerability has only been confirmed in version 1.7.19 but may also affect other versions."},"relatedVulnerabilities":[]},{"artifact":{"id":"fd17686e5bed5aa5","cpes":["cpe:2.3:a:coreutils:coreutils:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.7-r1?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/chcon"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/runcon"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a082454f2af64147","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"684b0dd3c2afb260","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"3c17affff9d77397","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"20eff52535634991","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1535c225c29ad6c","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"10da0231daa08e01","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"20eff52535634991","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1535c225c29ad6c","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"10da0231daa08e01","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10966","versionConstraint":">= 7.69.0, < 8.16.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10966","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10966","cwe":"CWE-322","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2025-10966","date":"2026-10-08","epss":0.00427,"percentile":0.34978}],"risk":0.198555,"urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-66037","versionConstraint":"<= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-66037","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66037","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66037","date":"2026-10-08","epss":0.00349,"percentile":0.26444}],"risk":0.19834833333333335,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627","https://www.vulncheck.com/advisories/ffmpeg-iamf-demuxer-uncontrolled-resource-consumption-via-mix-presentation-obu"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66037","description":"FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14181","versionConstraint":">= 8.2.0, < 8.2.34||>= 8.3.0, < 8.3.35||>= 8.4.0, < 8.4.26||>= 8.5.0, < 8.5.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14181","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security@php.net","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14181","cwe":"CWE-190","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2025-14181","date":"2026-10-08","epss":0.00341,"percentile":0.25575}],"risk":0.19607499999999997,"urls":["https://github.com/php/php-src/security/advisories/GHSA-cj93-vc83-wgqv"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14181","description":"The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-4873","versionConstraint":">= 7.20.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"risk":0.195655,"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."},"relatedVulnerabilities":[]},{"artifact":{"id":"b00e0f2cdd6f77b0","cpes":["cpe:2.3:a:pcre2:pcre2:10.46-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.46-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.46-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.46-r0:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.46-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"10.46-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.14.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.6"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-89157","versionConstraint":">= 10.30, < 10.48||= 10.48-rc1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:pcre:pcre2:10.46:*:*:*:*:*:*:*"],"package":{"name":"pcre2","version":"10.46-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.195295,"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-92842","versionConstraint":">= 8.2.0, < 8.2.34||>= 8.3.0, < 8.3.35||>= 8.4.0, < 8.4.26||>= 8.5.0, < 8.5.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-92842","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security@php.net","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-92842","cwe":"CWE-122","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-92842","cwe":"CWE-125","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-92842","date":"2026-10-08","epss":0.00357,"percentile":0.27336}],"risk":0.194565,"urls":["https://github.com/php/php-src/security/advisories/GHSA-88hq-2827-7pg6"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-92842","description":"The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-0518","versionConstraint":"< 3.4.14||>= 4.0, < 4.2.11||>= 4.3, < 4.3.9||>= 4.4, < 4.4.6||>= 5.0, < 5.1.7||>= 6.0, < 6.1.3||>= 7.0, < 7.0.3||>= 7.1, < 7.1.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-0518","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0518","cwe":"CWE-125","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"},{"cve":"CVE-2025-0518","cwe":"CWE-252","type":"Secondary","source":"96148269-fe82-4198-b1bf-3a73ce8bc92e"}],"epss":[{"cve":"CVE-2025-0518","date":"2026-10-08","epss":0.00386,"percentile":0.30503}],"risk":0.19396499999999997,"urls":["https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a","https://lists.debian.org/debian-lts-announce/2025/02/msg00037.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518","description":"Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman"},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42528","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-42528","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"risk":0.19343999999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-42528"},"relatedVulnerabilities":[{"id":"CVE-2026-42528","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/12"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-17545","versionConstraint":">= 8.2.0, < 8.2.34||>= 8.3.0, < 8.3.35||>= 8.4.0, < 8.4.26||>= 8.5.0, < 8.5.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-17545","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17545","cwe":"CWE-67","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-17545","date":"2026-10-08","epss":0.00322,"percentile":0.23238}],"risk":0.19159,"urls":["https://github.com/php/php-src/security/advisories/GHSA-9f67-6fw4-hpfp"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17545","description":"On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-93682","versionConstraint":">= 8.2.0, < 8.2.34||>= 8.3.0, < 8.3.35||>= 8.4.0, < 8.4.26||>= 8.5.0, < 8.5.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-93682","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security@php.net","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","metrics":{"baseScore":5.8,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93682","cwe":"CWE-125","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-93682","date":"2026-10-08","epss":0.00354,"percentile":0.27092}],"risk":0.19116000000000002,"urls":["https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93682","description":"When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory."},"relatedVulnerabilities":[]},{"artifact":{"id":"4619ae3aa570ed9c","cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:tiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:libtiff:4.7.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:tiff:tiff:4.7.1-r0:*:*:*:*:*:*:*"],"name":"tiff","purl":"pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"4.7.1-r0","language":"","licenses":["libtiff"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libtiff.so.6"},{"path":"/usr/lib/libtiff.so.6.2.0"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"tiff"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6228","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libtiff:libtiff:4.7.1:*:*:*:*:*:*:*"],"package":{"name":"tiff","version":"4.7.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6228","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6228","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-6228","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6228","date":"2026-10-08","epss":0.00399,"percentile":0.32024}],"risk":0.18752999999999997,"urls":["https://access.redhat.com/errata/RHSA-2024:2289","https://access.redhat.com/errata/RHSA-2024:5079","https://access.redhat.com/security/cve/CVE-2023-6228","https://bugzilla.redhat.com/show_bug.cgi?id=2240995"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6228","description":"An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash."},"relatedVulnerabilities":[]},{"artifact":{"id":"d8355efc685c2f33","cpes":["cpe:2.3:a:phpseclib\\/phpseclib:phpseclib\\/phpseclib:3.0.55:*:*:*:*:*:*:*"],"name":"phpseclib/phpseclib","purl":"pkg:composer/phpseclib/phpseclib@3.0.55","type":"php-composer","version":"3.0.55","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www/src/3rdparty/composer/installed.json","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/app/www/src/3rdparty/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.57"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q97c-8qh3-fpc6","versionConstraint":"<3.0.57 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"phpseclib/phpseclib","version":"3.0.55"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-q97c-8qh3-fpc6","fix":{"state":"fixed","versions":["3.0.57"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.0.57"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84308","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84308","cwe":"CWE-385","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84308","date":"2026-10-08","epss":0.00327,"percentile":0.23755}],"risk":0.18475499999999997,"urls":["https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6","https://nvd.nist.gov/vuln/detail/CVE-2026-84308","https://github.com/phpseclib/phpseclib/commit/fb56bc5bb9009b54a6c26b31aeec8ed944f17373","https://github.com/phpseclib/phpseclib/releases/tag/3.0.57","https://github.com/phpseclib/phpseclib/releases/tag/4.0.1"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q97c-8qh3-fpc6","description":"phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery"},"relatedVulnerabilities":[{"id":"CVE-2026-84308","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84308","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84308","cwe":"CWE-385","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84308","date":"2026-10-08","epss":0.00327,"percentile":0.23755}],"urls":["https://github.com/phpseclib/phpseclib/commit/fb56bc5bb9009b54a6c26b31aeec8ed944f17373","https://github.com/phpseclib/phpseclib/releases/tag/3.0.57","https://github.com/phpseclib/phpseclib/releases/tag/4.0.1","https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84308","description":"phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and subtract(). During the Montgomery ladder in phpseclib/Crypt/EC/BaseCurves/Montgomery.php, the reduction behavior of each step depends on the secret scalar prefix, creating per-step timing and libgmp call-count observations that can reveal a reused 251-bit clamped private scalar. The phpseclib/Crypt/EC/Formats/Keys/MontgomeryPrivate.php derivation path invokes the pure-PHP multiplication without a native-engine check, while phpseclib/Crypt/EC/Formats/Keys/PKCS8.php reaches it when ext-sodium is unavailable. Exploitation requires a reused or long-lived X25519 private key, knowledge of the corresponding public key, execution of the pure-PHP path, and a local observer capable of resolving individual ladder steps or libgmp entry-point calls. Ephemeral X25519 keys, including phpseclib's normal SSH exchange path, are not affected. Recovery of the scalar permanently compromises operations that reuse that key. This issue is fixed in versions 3.0.57 and 4.0.1."}]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-91766","versionConstraint":">= 8.2.0, < 8.2.34||>= 8.3.0, < 8.3.35||>= 8.4.0, < 8.4.26||>= 8.5.0, < 8.5.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-91766","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security@php.net","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91766","cwe":"CWE-200","type":"Secondary","source":"security@php.net"},{"cve":"CVE-2026-91766","cwe":"CWE-522","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-91766","date":"2026-10-08","epss":0.00338,"percentile":0.25169}],"risk":0.18421,"urls":["https://github.com/php/php-src/security/advisories/GHSA-fpwc-w8rq-cr92"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91766","description":"When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f )."},"relatedVulnerabilities":[]},{"artifact":{"id":"20eff52535634991","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1535c225c29ad6c","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"10da0231daa08e01","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6735","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6735","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:L/U:Amber","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6735","cwe":"CWE-79","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-6735","date":"2026-10-08","epss":0.00309,"percentile":0.21796}],"risk":0.18076499999999998,"urls":["https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6735","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-62986","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-62986","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-62986","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-62986","date":"2026-10-08","epss":0.0038,"percentile":0.29898}],"risk":0.1767,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/36ff0968de08d7ae80792f9f53402f93433207bb","https://github.com/AcademySoftwareFoundation/openexr/commit/5105809507ba572d8cad12ec9f5a5c9d378354b9","https://github.com/AcademySoftwareFoundation/openexr/commit/5a534e2228c853034e5cb9d2599ebf82f48f51b0","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pf59-r2mc-x746"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-62986","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses layer-prefixed RGB channels. With the default channel coalescing (separate_channels=False), the wrapper groups channels such as left.R, left.G, and left.B into a single RGB sample array, but the lane-offset calculation in PyPart::setDeepSliceData() only recognizes the exact unprefixed names G, B, and A. As a result, prefixed channels like left.G and left.B are decoded into lane 0 while lanes 1 and 2 are left uninitialized and returned to Python. A Python application that reads untrusted deep EXR files through the default OpenEXR.File API and then logs, serializes, previews, or otherwise processes the resulting NumPy sample arrays may expose uninitialized same-process heap contents, in addition to receiving incorrect green and blue channel data. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-62986","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-62986","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-62986","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-62986","date":"2026-10-08","epss":0.0038,"percentile":0.29898}],"risk":0.1767,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/36ff0968de08d7ae80792f9f53402f93433207bb","https://github.com/AcademySoftwareFoundation/openexr/commit/5105809507ba572d8cad12ec9f5a5c9d378354b9","https://github.com/AcademySoftwareFoundation/openexr/commit/5a534e2228c853034e5cb9d2599ebf82f48f51b0","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pf59-r2mc-x746"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-62986","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses layer-prefixed RGB channels. With the default channel coalescing (separate_channels=False), the wrapper groups channels such as left.R, left.G, and left.B into a single RGB sample array, but the lane-offset calculation in PyPart::setDeepSliceData() only recognizes the exact unprefixed names G, B, and A. As a result, prefixed channels like left.G and left.B are decoded into lane 0 while lanes 1 and 2 are left uninitialized and returned to Python. A Python application that reads untrusted deep EXR files through the default OpenEXR.File API and then logs, serializes, previews, or otherwise processes the resulting NumPy sample arrays may expose uninitialized same-process heap contents, in addition to receiving incorrect green and blue channel data. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-62986","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-62986","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-62986","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-62986","date":"2026-10-08","epss":0.0038,"percentile":0.29898}],"risk":0.1767,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/36ff0968de08d7ae80792f9f53402f93433207bb","https://github.com/AcademySoftwareFoundation/openexr/commit/5105809507ba572d8cad12ec9f5a5c9d378354b9","https://github.com/AcademySoftwareFoundation/openexr/commit/5a534e2228c853034e5cb9d2599ebf82f48f51b0","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pf59-r2mc-x746"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-62986","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses layer-prefixed RGB channels. With the default channel coalescing (separate_channels=False), the wrapper groups channels such as left.R, left.G, and left.B into a single RGB sample array, but the lane-offset calculation in PyPart::setDeepSliceData() only recognizes the exact unprefixed names G, B, and A. As a result, prefixed channels like left.G and left.B are decoded into lane 0 while lanes 1 and 2 are left uninitialized and returned to Python. A Python application that reads untrusted deep EXR files through the default OpenEXR.File API and then logs, serializes, previews, or otherwise processes the resulting NumPy sample arrays may expose uninitialized same-process heap contents, in addition to receiving incorrect green and blue channel data. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-62986","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-62986","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-62986","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-457","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-62986","cwe":"CWE-908","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-62986","date":"2026-10-08","epss":0.0038,"percentile":0.29898}],"risk":0.1767,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/36ff0968de08d7ae80792f9f53402f93433207bb","https://github.com/AcademySoftwareFoundation/openexr/commit/5105809507ba572d8cad12ec9f5a5c9d378354b9","https://github.com/AcademySoftwareFoundation/openexr/commit/5a534e2228c853034e5cb9d2599ebf82f48f51b0","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pf59-r2mc-x746"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-62986","description":"OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses layer-prefixed RGB channels. With the default channel coalescing (separate_channels=False), the wrapper groups channels such as left.R, left.G, and left.B into a single RGB sample array, but the lane-offset calculation in PyPart::setDeepSliceData() only recognizes the exact unprefixed names G, B, and A. As a result, prefixed channels like left.G and left.B are decoded into lane 0 while lanes 1 and 2 are left uninitialized and returned to Python. A Python application that reads untrusted deep EXR files through the default OpenEXR.File API and then logs, serializes, previews, or otherwise processes the resulting NumPy sample arrays may expose uninitialized same-process heap contents, in addition to receiving incorrect green and blue channel data. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"4e63a2c4b6f1c98e","cpes":["cpe:2.3:a:libssh:libssh:0.11.2-r0:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:apk/alpine/libssh@0.11.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"0.11.2-r0","language":"","licenses":["BSD-2-Clause","LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssh.so.4"},{"path":"/usr/lib/libssh.so.4.10.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-59848","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:libssh:libssh:0.11.2:*:*:*:*:*:*:*"],"package":{"name":"libssh","version":"0.11.2-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-59848","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59848","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59848","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59848","date":"2026-10-08","epss":0.00341,"percentile":0.25513}],"risk":0.175615,"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59848","https://bugzilla.redhat.com/show_bug.cgi?id=2498181"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59848","description":"A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"2a3b9c07c7f4cf56","cpes":["cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*"],"name":"nghttp2-libs","purl":"pkg:apk/alpine/nghttp2-libs@1.69.0-r0?arch=x86_64&distro=alpine-3.22.6&upstream=nghttp2","type":"apk","version":"1.69.0-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libnghttp2.so.14"},{"path":"/usr/lib/libnghttp2.so.14.29.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nghttp2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58055","versionConstraint":"<= 1.69.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:nghttp2:nghttp2:1.69.0:*:*:*:*:*:*:*"],"package":{"name":"nghttp2","version":"1.69.0-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"risk":0.1730575,"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[]},{"artifact":{"id":"223fa6c66161090f","cpes":["cpe:2.3:a:avahi-libs:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi-libs:avahi_libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi_libs:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi_libs:avahi_libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi:avahi-libs:0.8-r21:*:*:*:*:*:*:*","cpe:2.3:a:avahi:avahi_libs:0.8-r21:*:*:*:*:*:*:*"],"name":"avahi-libs","purl":"pkg:apk/alpine/avahi-libs@0.8-r21?arch=x86_64&distro=alpine-3.22.6&upstream=avahi","type":"apk","version":"0.8-r21","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavahi-client.so.3"},{"path":"/usr/lib/libavahi-client.so.3.2.9"},{"path":"/usr/lib/libavahi-common.so.3"},{"path":"/usr/lib/libavahi-common.so.3.5.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"avahi"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-24401","versionConstraint":"< 0.9||= 0.9-rc1||= 0.9-rc2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:avahi:avahi:0.8:*:*:*:*:*:*:*"],"package":{"name":"avahi","version":"0.8-r21"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-24401","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24401","date":"2026-10-08","epss":0.00296,"percentile":0.20454}],"risk":0.17019999999999996,"urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524."},"relatedVulnerabilities":[]},{"artifact":{"id":"20eff52535634991","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1535c225c29ad6c","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"10da0231daa08e01","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"477bdffcdb4cd0d4","cpes":["cpe:2.3:a:ghostscript:ghostscript:10.05.1-r0:*:*:*:*:*:*:*","cpe:2.3:a:artifex:ghostscript:10.05.1-r0:*:*:*:*:*:*:*"],"name":"ghostscript","purl":"pkg:apk/alpine/ghostscript@10.05.1-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"10.05.1-r0","language":"","licenses":["AGPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/dvipdf"},{"path":"/usr/bin/eps2eps"},{"path":"/usr/bin/gs"},{"path":"/usr/bin/gsbj"},{"path":"/usr/bin/gsc"},{"path":"/usr/bin/gsdj"},{"path":"/usr/bin/gsdj500"},{"path":"/usr/bin/gslj"},{"path":"/usr/bin/gslp"},{"path":"/usr/bin/gsnd"},{"path":"/usr/bin/ijs_client_example"},{"path":"/usr/bin/ijs_server_example"},{"path":"/usr/bin/lprsetup.sh"},{"path":"/usr/bin/pdf2dsc"},{"path":"/usr/bin/pdf2ps"},{"path":"/usr/bin/pf2afm"},{"path":"/usr/bin/pfbtopfa"},{"path":"/usr/bin/pphs"},{"path":"/usr/bin/printafm"},{"path":"/usr/bin/ps2ascii"},{"path":"/usr/bin/ps2epsi"},{"path":"/usr/bin/ps2pdf"},{"path":"/usr/bin/ps2pdf12"},{"path":"/usr/bin/ps2pdf13"},{"path":"/usr/bin/ps2pdf14"},{"path":"/usr/bin/ps2pdfwr"},{"path":"/usr/bin/ps2ps"},{"path":"/usr/bin/ps2ps2"},{"path":"/usr/bin/unix-lpr.sh"},{"path":"/usr/lib"},{"path":"/usr/lib/libgs.so.10"},{"path":"/usr/lib/libgs.so.10.05"},{"path":"/usr/lib/libijs-0.35.so"},{"path":"/usr/share"},{"path":"/usr/share/fonts"},{"path":"/usr/share/fonts/Type1"},{"path":"/usr/share/ghostscript"},{"path":"/usr/share/ghostscript/Resource"},{"path":"/usr/share/ghostscript/Resource/CIDFSubst"},{"path":"/usr/share/ghostscript/Resource/CIDFSubst/DroidSansFallback.ttf"},{"path":"/usr/share/ghostscript/Resource/CIDFont"},{"path":"/usr/share/ghostscript/Resource/CIDFont/ArtifexBullet"},{"path":"/usr/share/ghostscript/Resource/CMap"},{"path":"/usr/share/ghostscript/Resource/CMap/78-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/78-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/78-H"},{"path":"/usr/share/ghostscript/Resource/CMap/78-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/78-RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/78-V"},{"path":"/usr/share/ghostscript/Resource/CMap/78ms-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/78ms-RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/83pv-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/90ms-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/90ms-RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/90msp-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/90msp-RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/90pv-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/90pv-RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Add-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Add-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Add-RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Add-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-0"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-1"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-2"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-3"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-4"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-5"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-6"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-CNS1-7"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-GB1-0"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-GB1-1"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-GB1-2"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-GB1-3"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-GB1-4"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-GB1-5"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan1-0"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan1-1"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan1-2"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan1-3"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan1-4"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan1-5"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan1-6"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Japan2-0"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Korea1-0"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Korea1-1"},{"path":"/usr/share/ghostscript/Resource/CMap/Adobe-Korea1-2"},{"path":"/usr/share/ghostscript/Resource/CMap/B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/B5pc-H"},{"path":"/usr/share/ghostscript/Resource/CMap/B5pc-V"},{"path":"/usr/share/ghostscript/Resource/CMap/CNS-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/CNS-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/CNS1-H"},{"path":"/usr/share/ghostscript/Resource/CMap/CNS1-V"},{"path":"/usr/share/ghostscript/Resource/CMap/CNS2-H"},{"path":"/usr/share/ghostscript/Resource/CMap/CNS2-V"},{"path":"/usr/share/ghostscript/Resource/CMap/ETHK-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/ETHK-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/ETen-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/ETen-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/ETenms-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/ETenms-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Ext-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Ext-RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Ext-RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Ext-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GB-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GB-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GB-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GB-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GBK-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GBK-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GBK2K-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GBK2K-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GBKp-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GBKp-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GBT-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GBT-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GBT-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GBT-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GBTpc-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GBTpc-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/GBpc-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/GBpc-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/H"},{"path":"/usr/share/ghostscript/Resource/CMap/HKdla-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/HKdla-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/HKdlb-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/HKdlb-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/HKgccs-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/HKgccs-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/HKm314-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/HKm314-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/HKm471-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/HKm471-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/HKscs-B5-H"},{"path":"/usr/share/ghostscript/Resource/CMap/HKscs-B5-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Hankaku"},{"path":"/usr/share/ghostscript/Resource/CMap/Hiragana"},{"path":"/usr/share/ghostscript/Resource/CMap/Hojo-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Hojo-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Hojo-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Hojo-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Identity-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Identity-UTF16-H"},{"path":"/usr/share/ghostscript/Resource/CMap/Identity-V"},{"path":"/usr/share/ghostscript/Resource/CMap/KSC-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/KSC-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/KSC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/KSC-Johab-H"},{"path":"/usr/share/ghostscript/Resource/CMap/KSC-Johab-V"},{"path":"/usr/share/ghostscript/Resource/CMap/KSC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/KSCms-UHC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/KSCms-UHC-HW-H"},{"path":"/usr/share/ghostscript/Resource/CMap/KSCms-UHC-HW-V"},{"path":"/usr/share/ghostscript/Resource/CMap/KSCms-UHC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/KSCpc-EUC-H"},{"path":"/usr/share/ghostscript/Resource/CMap/KSCpc-EUC-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Katakana"},{"path":"/usr/share/ghostscript/Resource/CMap/NWP-H"},{"path":"/usr/share/ghostscript/Resource/CMap/NWP-V"},{"path":"/usr/share/ghostscript/Resource/CMap/RKSJ-H"},{"path":"/usr/share/ghostscript/Resource/CMap/RKSJ-V"},{"path":"/usr/share/ghostscript/Resource/CMap/Roman"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UCS2-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UCS2-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UTF16-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UTF16-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UTF8-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniCNS-UTF8-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UCS2-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UCS2-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UTF16-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UTF16-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UTF8-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniGB-UTF8-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UCS2-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UCS2-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UTF16-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UTF16-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UTF8-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniHojo-UTF8-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UCS2-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UCS2-HW-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UCS2-HW-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UCS2-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UTF16-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UTF16-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UTF8-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS-UTF8-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS2004-UTF16-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS2004-UTF16-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS2004-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS2004-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS2004-UTF8-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJIS2004-UTF8-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJISPro-UCS2-HW-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJISPro-UCS2-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJISPro-UTF8-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJISX0213-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJISX0213-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJISX02132004-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniJISX02132004-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UCS2-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UCS2-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UTF16-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UTF16-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UTF32-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UTF32-V"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UTF8-H"},{"path":"/usr/share/ghostscript/Resource/CMap/UniKS-UTF8-V"},{"path":"/usr/share/ghostscript/Resource/CMap/V"},{"path":"/usr/share/ghostscript/Resource/CMap/WP-Symbol"},{"path":"/usr/share/ghostscript/Resource/ColorSpace"},{"path":"/usr/share/ghostscript/Resource/ColorSpace/DefaultCMYK"},{"path":"/usr/share/ghostscript/Resource/ColorSpace/DefaultGray"},{"path":"/usr/share/ghostscript/Resource/ColorSpace/DefaultRGB"},{"path":"/usr/share/ghostscript/Resource/ColorSpace/TrivialCMYK"},{"path":"/usr/share/ghostscript/Resource/ColorSpace/sGray"},{"path":"/usr/share/ghostscript/Resource/ColorSpace/sRGB"},{"path":"/usr/share/ghostscript/Resource/Decoding"},{"path":"/usr/share/ghostscript/Resource/Decoding/FCO_Dingbats"},{"path":"/usr/share/ghostscript/Resource/Decoding/FCO_Symbol"},{"path":"/usr/share/ghostscript/Resource/Decoding/FCO_Unicode"},{"path":"/usr/share/ghostscript/Resource/Decoding/FCO_Wingdings"},{"path":"/usr/share/ghostscript/Resource/Decoding/Latin1"},{"path":"/usr/share/ghostscript/Resource/Decoding/StandardEncoding"},{"path":"/usr/share/ghostscript/Resource/Decoding/Unicode"},{"path":"/usr/share/ghostscript/Resource/Encoding"},{"path":"/usr/share/ghostscript/Resource/Encoding/CEEncoding"},{"path":"/usr/share/ghostscript/Resource/Encoding/ExpertEncoding"},{"path":"/usr/share/ghostscript/Resource/Encoding/ExpertSubsetEncoding"},{"path":"/usr/share/ghostscript/Resource/Encoding/NotDefEncoding"},{"path":"/usr/share/ghostscript/Resource/Encoding/Wingdings"},{"path":"/usr/share/ghostscript/Resource/Font"},{"path":"/usr/share/ghostscript/Resource/Font/C059-BdIta"},{"path":"/usr/share/ghostscript/Resource/Font/C059-Bold"},{"path":"/usr/share/ghostscript/Resource/Font/C059-Italic"},{"path":"/usr/share/ghostscript/Resource/Font/C059-Roman"},{"path":"/usr/share/ghostscript/Resource/Font/D050000L"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusMonoPS-Bold"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusMonoPS-BoldItalic"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusMonoPS-Italic"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusMonoPS-Regular"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusRoman-Bold"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusRoman-BoldItalic"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusRoman-Italic"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusRoman-Regular"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSans-Bold"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSans-BoldItalic"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSans-Italic"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSans-Regular"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSansNarrow-Bold"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSansNarrow-BoldOblique"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSansNarrow-Oblique"},{"path":"/usr/share/ghostscript/Resource/Font/NimbusSansNarrow-Regular"},{"path":"/usr/share/ghostscript/Resource/Font/P052-Bold"},{"path":"/usr/share/ghostscript/Resource/Font/P052-BoldItalic"},{"path":"/usr/share/ghostscript/Resource/Font/P052-Italic"},{"path":"/usr/share/ghostscript/Resource/Font/P052-Roman"},{"path":"/usr/share/ghostscript/Resource/Font/StandardSymbolsPS"},{"path":"/usr/share/ghostscript/Resource/Font/URWBookman-Demi"},{"path":"/usr/share/ghostscript/Resource/Font/URWBookman-DemiItalic"},{"path":"/usr/share/ghostscript/Resource/Font/URWBookman-Light"},{"path":"/usr/share/ghostscript/Resource/Font/URWBookman-LightItalic"},{"path":"/usr/share/ghostscript/Resource/Font/URWGothic-Book"},{"path":"/usr/share/ghostscript/Resource/Font/URWGothic-BookOblique"},{"path":"/usr/share/ghostscript/Resource/Font/URWGothic-Demi"},{"path":"/usr/share/ghostscript/Resource/Font/URWGothic-DemiOblique"},{"path":"/usr/share/ghostscript/Resource/Font/Z003-MediumItalic"},{"path":"/usr/share/ghostscript/Resource/IdiomSet"},{"path":"/usr/share/ghostscript/Resource/IdiomSet/PPI_CUtils"},{"path":"/usr/share/ghostscript/Resource/IdiomSet/Pscript5Idiom"},{"path":"/usr/share/ghostscript/Resource/Init"},{"path":"/usr/share/ghostscript/Resource/Init/FAPIcidfmap"},{"path":"/usr/share/ghostscript/Resource/Init/FAPIconfig"},{"path":"/usr/share/ghostscript/Resource/Init/FAPIfontmap"},{"path":"/usr/share/ghostscript/Resource/Init/FCOfontmap-PCLPS2"},{"path":"/usr/share/ghostscript/Resource/Init/Fontmap"},{"path":"/usr/share/ghostscript/Resource/Init/Fontmap.GS"},{"path":"/usr/share/ghostscript/Resource/Init/cidfmap"},{"path":"/usr/share/ghostscript/Resource/Init/gs_agl.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_btokn.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cet.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cff.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cidcm.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_ciddc.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cidfm.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cidfn.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cidtt.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cmap.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_cspace.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_dbt_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_diskn.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_dps1.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_dps2.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_dscp.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_epsf.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_fapi.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_fntem.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_fonts.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_frsd.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_icc.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_il1_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_img.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_init.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_lev2.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_ll3.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_mex_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_mgl_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_mro_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_pdf_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_pdfwr.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_res.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_resmp.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_setpd.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_statd.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_std_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_sym_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_trap.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_ttf.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_typ32.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_typ42.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_type1.ps"},{"path":"/usr/share/ghostscript/Resource/Init/gs_wan_e.ps"},{"path":"/usr/share/ghostscript/Resource/Init/pdf_main.ps"},{"path":"/usr/share/ghostscript/Resource/Init/xlatmap"},{"path":"/usr/share/ghostscript/Resource/SubstCID"},{"path":"/usr/share/ghostscript/Resource/SubstCID/CNS1-WMode"},{"path":"/usr/share/ghostscript/Resource/SubstCID/GB1-WMode"},{"path":"/usr/share/ghostscript/Resource/SubstCID/Japan1-WMode"},{"path":"/usr/share/ghostscript/Resource/SubstCID/Korea1-WMode"},{"path":"/usr/share/ghostscript/iccprofiles"},{"path":"/usr/share/ghostscript/iccprofiles/a98.icc"},{"path":"/usr/share/ghostscript/iccprofiles/default_cmyk.icc"},{"path":"/usr/share/ghostscript/iccprofiles/default_gray.icc"},{"path":"/usr/share/ghostscript/iccprofiles/default_rgb.icc"},{"path":"/usr/share/ghostscript/iccprofiles/esrgb.icc"},{"path":"/usr/share/ghostscript/iccprofiles/gray_to_k.icc"},{"path":"/usr/share/ghostscript/iccprofiles/lab.icc"},{"path":"/usr/share/ghostscript/iccprofiles/ps_cmyk.icc"},{"path":"/usr/share/ghostscript/iccprofiles/ps_gray.icc"},{"path":"/usr/share/ghostscript/iccprofiles/ps_rgb.icc"},{"path":"/usr/share/ghostscript/iccprofiles/rommrgb.icc"},{"path":"/usr/share/ghostscript/iccprofiles/scrgb.icc"},{"path":"/usr/share/ghostscript/iccprofiles/sgray.icc"},{"path":"/usr/share/ghostscript/iccprofiles/srgb.icc"},{"path":"/usr/share/ghostscript/lib"},{"path":"/usr/share/ghostscript/lib/PDFA_def.ps"},{"path":"/usr/share/ghostscript/lib/PDFX_def.ps"},{"path":"/usr/share/ghostscript/lib/PM760p.upp"},{"path":"/usr/share/ghostscript/lib/PM760pl.upp"},{"path":"/usr/share/ghostscript/lib/PM820p.upp"},{"path":"/usr/share/ghostscript/lib/PM820pl.upp"},{"path":"/usr/share/ghostscript/lib/Stc670p.upp"},{"path":"/usr/share/ghostscript/lib/Stc670pl.upp"},{"path":"/usr/share/ghostscript/lib/Stc680p.upp"},{"path":"/usr/share/ghostscript/lib/Stc680pl.upp"},{"path":"/usr/share/ghostscript/lib/Stc740p.upp"},{"path":"/usr/share/ghostscript/lib/Stc740pl.upp"},{"path":"/usr/share/ghostscript/lib/Stc760p.upp"},{"path":"/usr/share/ghostscript/lib/Stc760pl.upp"},{"path":"/usr/share/ghostscript/lib/Stc777p.upp"},{"path":"/usr/share/ghostscript/lib/Stc777pl.upp"},{"path":"/usr/share/ghostscript/lib/Stp720p.upp"},{"path":"/usr/share/ghostscript/lib/Stp720pl.upp"},{"path":"/usr/share/ghostscript/lib/Stp870p.upp"},{"path":"/usr/share/ghostscript/lib/Stp870pl.upp"},{"path":"/usr/share/ghostscript/lib/acctest.ps"},{"path":"/usr/share/ghostscript/lib/align.ps"},{"path":"/usr/share/ghostscript/lib/bj8.rpd"},{"path":"/usr/share/ghostscript/lib/bj8gc12f.upp"},{"path":"/usr/share/ghostscript/lib/bj8hg12f.upp"},{"path":"/usr/share/ghostscript/lib/bj8oh06n.upp"},{"path":"/usr/share/ghostscript/lib/bj8pa06n.upp"},{"path":"/usr/share/ghostscript/lib/bj8pp12f.upp"},{"path":"/usr/share/ghostscript/lib/bj8ts06n.upp"},{"path":"/usr/share/ghostscript/lib/bjc6000a1.upp"},{"path":"/usr/share/ghostscript/lib/bjc6000b1.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a0.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a1.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a2.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a3.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a4.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a5.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a6.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a7.upp"},{"path":"/usr/share/ghostscript/lib/bjc610a8.upp"},{"path":"/usr/share/ghostscript/lib/bjc610b1.upp"},{"path":"/usr/share/ghostscript/lib/bjc610b2.upp"},{"path":"/usr/share/ghostscript/lib/bjc610b3.upp"},{"path":"/usr/share/ghostscript/lib/bjc610b4.upp"},{"path":"/usr/share/ghostscript/lib/bjc610b6.upp"},{"path":"/usr/share/ghostscript/lib/bjc610b7.upp"},{"path":"/usr/share/ghostscript/lib/bjc610b8.upp"},{"path":"/usr/share/ghostscript/lib/caption.ps"},{"path":"/usr/share/ghostscript/lib/cbjc600.ppd"},{"path":"/usr/share/ghostscript/lib/cbjc800.ppd"},{"path":"/usr/share/ghostscript/lib/cdj550.upp"},{"path":"/usr/share/ghostscript/lib/cdj690.upp"},{"path":"/usr/share/ghostscript/lib/cdj690ec.upp"},{"path":"/usr/share/ghostscript/lib/cid2code.ps"},{"path":"/usr/share/ghostscript/lib/dnj750c.upp"},{"path":"/usr/share/ghostscript/lib/dnj750m.upp"},{"path":"/usr/share/ghostscript/lib/docie.ps"},{"path":"/usr/share/ghostscript/lib/font2pcl.ps"},{"path":"/usr/share/ghostscript/lib/ghostpdf.ppd"},{"path":"/usr/share/ghostscript/lib/gs_ce_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_css_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_il2_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_kanji.ps"},{"path":"/usr/share/ghostscript/lib/gs_ksb_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_l.xbm"},{"path":"/usr/share/ghostscript/lib/gs_l.xpm"},{"path":"/usr/share/ghostscript/lib/gs_l_m.xbm"},{"path":"/usr/share/ghostscript/lib/gs_lgo_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_lgx_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_m.xbm"},{"path":"/usr/share/ghostscript/lib/gs_m.xpm"},{"path":"/usr/share/ghostscript/lib/gs_m_m.xbm"},{"path":"/usr/share/ghostscript/lib/gs_s.xbm"},{"path":"/usr/share/ghostscript/lib/gs_s.xpm"},{"path":"/usr/share/ghostscript/lib/gs_s_m.xbm"},{"path":"/usr/share/ghostscript/lib/gs_t.xbm"},{"path":"/usr/share/ghostscript/lib/gs_t.xpm"},{"path":"/usr/share/ghostscript/lib/gs_t_m.xbm"},{"path":"/usr/share/ghostscript/lib/gs_wl1_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_wl2_e.ps"},{"path":"/usr/share/ghostscript/lib/gs_wl5_e.ps"},{"path":"/usr/share/ghostscript/lib/gslp.ps"},{"path":"/usr/share/ghostscript/lib/gsnup.ps"},{"path":"/usr/share/ghostscript/lib/ht_ccsto.ps"},{"path":"/usr/share/ghostscript/lib/image-qa.ps"},{"path":"/usr/share/ghostscript/lib/jispaper.ps"},{"path":"/usr/share/ghostscript/lib/landscap.ps"},{"path":"/usr/share/ghostscript/lib/lines.ps"},{"path":"/usr/share/ghostscript/lib/mkcidfm.ps"},{"path":"/usr/share/ghostscript/lib/necp2x.upp"},{"path":"/usr/share/ghostscript/lib/necp2x6.upp"},{"path":"/usr/share/ghostscript/lib/pdf2dsc.ps"},{"path":"/usr/share/ghostscript/lib/pdf_info.ps"},{"path":"/usr/share/ghostscript/lib/pf2afm.ps"},{"path":"/usr/share/ghostscript/lib/pfbtopfa.ps"},{"path":"/usr/share/ghostscript/lib/ppath.ps"},{"path":"/usr/share/ghostscript/lib/pphs.ps"},{"path":"/usr/share/ghostscript/lib/prfont.ps"},{"path":"/usr/share/ghostscript/lib/printafm.ps"},{"path":"/usr/share/ghostscript/lib/ps2ai.ps"},{"path":"/usr/share/ghostscript/lib/ps2epsi.ps"},{"path":"/usr/share/ghostscript/lib/ras1.upp"},{"path":"/usr/share/ghostscript/lib/ras24.upp"},{"path":"/usr/share/ghostscript/lib/ras3.upp"},{"path":"/usr/share/ghostscript/lib/ras32.upp"},{"path":"/usr/share/ghostscript/lib/ras4.upp"},{"path":"/usr/share/ghostscript/lib/ras8m.upp"},{"path":"/usr/share/ghostscript/lib/rollconv.ps"},{"path":"/usr/share/ghostscript/lib/s400a1.upp"},{"path":"/usr/share/ghostscript/lib/s400b1.upp"},{"path":"/usr/share/ghostscript/lib/sharp.upp"},{"path":"/usr/share/ghostscript/lib/sipixa6.upp"},{"path":"/usr/share/ghostscript/lib/st640ih.upp"},{"path":"/usr/share/ghostscript/lib/st640ihg.upp"},{"path":"/usr/share/ghostscript/lib/st640p.upp"},{"path":"/usr/share/ghostscript/lib/st640pg.upp"},{"path":"/usr/share/ghostscript/lib/st640pl.upp"},{"path":"/usr/share/ghostscript/lib/st640plg.upp"},{"path":"/usr/share/ghostscript/lib/stc.upp"},{"path":"/usr/share/ghostscript/lib/stc1520h.upp"},{"path":"/usr/share/ghostscript/lib/stc2.upp"},{"path":"/usr/share/ghostscript/lib/stc200_h.upp"},{"path":"/usr/share/ghostscript/lib/stc2_h.upp"},{"path":"/usr/share/ghostscript/lib/stc2s_h.upp"},{"path":"/usr/share/ghostscript/lib/stc300.upp"},{"path":"/usr/share/ghostscript/lib/stc300bl.upp"},{"path":"/usr/share/ghostscript/lib/stc300bm.upp"},{"path":"/usr/share/ghostscript/lib/stc500p.upp"},{"path":"/usr/share/ghostscript/lib/stc500ph.upp"},{"path":"/usr/share/ghostscript/lib/stc600ih.upp"},{"path":"/usr/share/ghostscript/lib/stc600p.upp"},{"path":"/usr/share/ghostscript/lib/stc600pl.upp"},{"path":"/usr/share/ghostscript/lib/stc640p.upp"},{"path":"/usr/share/ghostscript/lib/stc740ih.upp"},{"path":"/usr/share/ghostscript/lib/stc800ih.upp"},{"path":"/usr/share/ghostscript/lib/stc800p.upp"},{"path":"/usr/share/ghostscript/lib/stc800pl.upp"},{"path":"/usr/share/ghostscript/lib/stc_h.upp"},{"path":"/usr/share/ghostscript/lib/stc_l.upp"},{"path":"/usr/share/ghostscript/lib/stcany.upp"},{"path":"/usr/share/ghostscript/lib/stcany_h.upp"},{"path":"/usr/share/ghostscript/lib/stcinfo.ps"},{"path":"/usr/share/ghostscript/lib/stcolor.ps"},{"path":"/usr/share/ghostscript/lib/stocht.ps"},{"path":"/usr/share/ghostscript/lib/traceimg.ps"},{"path":"/usr/share/ghostscript/lib/traceop.ps"},{"path":"/usr/share/ghostscript/lib/uninfo.ps"},{"path":"/usr/share/ghostscript/lib/viewcmyk.ps"},{"path":"/usr/share/ghostscript/lib/viewgif.ps"},{"path":"/usr/share/ghostscript/lib/viewjpeg.ps"},{"path":"/usr/share/ghostscript/lib/viewmiff.ps"},{"path":"/usr/share/ghostscript/lib/viewpbm.ps"},{"path":"/usr/share/ghostscript/lib/viewpcx.ps"},{"path":"/usr/share/ghostscript/lib/viewps2a.ps"},{"path":"/usr/share/ghostscript/lib/winmaps.ps"},{"path":"/usr/share/ghostscript/lib/zeroline.ps"},{"path":"/usr/share/ghostscript/lib/zugferd.ps"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ghostscript"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-38560","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:artifex:ghostscript:10.05.1:*:*:*:*:*:*:*"],"package":{"name":"ghostscript","version":"10.05.1-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-38560","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-38560","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-38560","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-38560","date":"2026-10-08","epss":0.00323,"percentile":0.23361}],"risk":0.169575,"urls":["https://access.redhat.com/security/cve/CVE-2023-38560","https://bugs.ghostscript.com/show_bug.cgi?id=706898","https://bugzilla.redhat.com/show_bug.cgi?id=2224368","https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=b7eb1d0174c"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-38560","description":"An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format."},"relatedVulnerabilities":[]},{"artifact":{"id":"196b0b96f9c259d7","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r20:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r20?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.37.0-r20","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r20"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"57f6a17b40a606dc","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r20:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r20?arch=x86_64&distro=alpine-3.22.6&upstream=busybox","type":"apk","version":"1.37.0-r20","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r20"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"749529783a76cce6","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r20:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r20?arch=x86_64&distro=alpine-3.22.6&upstream=busybox","type":"apk","version":"1.37.0-r20","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r20"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10256","versionConstraint":">= 3.2, < 8.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10256","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"patrick@puiterwijk.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10256","cwe":"CWE-476","type":"Secondary","source":"patrick@puiterwijk.org"}],"epss":[{"cve":"CVE-2025-10256","date":"2026-10-08","epss":0.00317,"percentile":0.22614}],"risk":0.16484000000000001,"urls":["https://access.redhat.com/security/cve/CVE-2025-10256","https://bugzilla.redhat.com/show_bug.cgi?id=2394495","https://github.com/FFmpeg/FFmpeg/commit/a25462482c02c004d685a8fcf2fa63955aaa0931","https://github.com/FFmpeg/FFmpeg/commit/d3be186ed1bcdcf2c093d6b13a0e66dc5132be2a"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256","description":"A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7259","versionConstraint":">= 8.2.0, < 8.2.31||>= 8.3.0, < 8.3.31||>= 8.4.0, < 8.4.21||>= 8.5.0, < 8.5.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7259","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7259","cwe":"CWE-476","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-7259","date":"2026-10-08","epss":0.00345,"percentile":0.25977}],"risk":0.16042499999999998,"urls":["https://github.com/php/php-src/security/advisories/GHSA-wm6j-2649-pv75"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7259","description":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding()."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-70632","versionConstraint":">= 4.4, < 9 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-70632","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70632","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70632","date":"2026-10-08","epss":0.00202,"percentile":0.09259}],"risk":0.158065,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898","https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70632","description":"FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer."},"relatedVulnerabilities":[]},{"artifact":{"id":"13a6ac35b7e9ab6a","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.22.6&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42356","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-42356","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"risk":0.15745,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-42356"},"relatedVulnerabilities":[{"id":"CVE-2026-42356","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/11"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-1965","versionConstraint":">= 7.10.6, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-1965","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"risk":0.1518,"urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API)."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12495","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12495","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12495","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12495","date":"2026-10-08","epss":0.00194,"percentile":0.08292}],"risk":0.14841000000000001,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-989/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12495","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27946."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12495","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12495","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12495","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12495","date":"2026-10-08","epss":0.00194,"percentile":0.08292}],"risk":0.14841000000000001,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-989/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12495","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27946."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12495","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12495","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12495","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12495","date":"2026-10-08","epss":0.00194,"percentile":0.08292}],"risk":0.14841000000000001,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-989/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12495","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27946."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12495","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12495","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12495","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12495","date":"2026-10-08","epss":0.00194,"percentile":0.08292}],"risk":0.14841000000000001,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-989/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12495","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27946."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12839","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12839","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12839","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12839","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-990/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12839","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27947."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12840","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12840","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12840","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12840","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-991/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12840","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27948."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12839","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12839","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12839","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12839","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-990/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12839","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27947."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12840","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12840","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12840","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12840","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-991/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12840","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27948."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12839","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12839","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12839","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12839","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-990/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12839","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27947."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12840","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12840","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12840","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12840","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-991/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12840","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27948."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12839","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12839","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12839","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12839","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-990/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12839","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27947."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-12840","versionConstraint":"< 3.4.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-12840","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"zdi-disclosures@trendmicro.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12840","cwe":"CWE-122","type":"Secondary","source":"zdi-disclosures@trendmicro.com"}],"epss":[{"cve":"CVE-2025-12840","date":"2026-10-08","epss":0.00192,"percentile":0.08129}],"risk":0.14688,"urls":["https://www.zerodayinitiative.com/advisories/ZDI-25-991/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12840","description":"Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27948."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15224","versionConstraint":">= 7.58.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15224","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-08","epss":0.0048,"percentile":0.39438}],"risk":0.14639999999999997,"urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65706","versionConstraint":">= 3.0, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65706","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65706","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65706","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65706","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1463275,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779","https://www.vulncheck.com/advisories/ffmpeg-vf-swaprect-out-of-bounds-write-via-nv12-frame-processing"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65706","description":"FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution."},"relatedVulnerabilities":[]},{"artifact":{"id":"81a44ddebb043d3c","cpes":["cpe:2.3:a:php84:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php84:php:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php84:8.4.16-r0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:8.4.16-r0:*:*:*:*:*:*:*"],"name":"php84","purl":"pkg:apk/alpine/php84@8.4.16-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.4.16-r0","language":"","licenses":["BSD-3-Clause","LGPL-2.0-or-later","MIT","PHP-3.01","Zend-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/php84"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"php84"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-14355","versionConstraint":">= 8.2.0, < 8.2.32||>= 8.3.0, < 8.3.32||>= 8.4.0, < 8.4.23||>= 8.5.0, < 8.5.8 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:php:php:8.4.16:*:*:*:*:*:*:*"],"package":{"name":"php84","version":"8.4.16-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-14355","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@php.net","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14355","cwe":"CWE-122","type":"Secondary","source":"security@php.net"}],"epss":[{"cve":"CVE-2026-14355","date":"2026-10-08","epss":0.00279,"percentile":0.18656}],"risk":0.1457775,"urls":["https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr","https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14355","description":"In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort."},"relatedVulnerabilities":[]},{"artifact":{"id":"b00e0f2cdd6f77b0","cpes":["cpe:2.3:a:pcre2:pcre2:10.46-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.46-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.46-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.46-r0:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.46-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"10.46-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.14.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.6"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-89158","versionConstraint":"< 10.48||= 10.48-rc1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:pcre:pcre2:10.46:*:*:*:*:*:*:*"],"package":{"name":"pcre2","version":"10.46-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.14202499999999998,"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-68513","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-68513","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68513","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68513","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68513","date":"2026-10-08","epss":0.00194,"percentile":0.08342}],"risk":0.14162,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/c1f3ec0d91cfa5a8035ecd00920835ac76e01640","https://github.com/AcademySoftwareFoundation/openexr/commit/d134e3cd81a2e343f2919e86bf949f576b1ab16a","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-rw5h-3q4v-c3vc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68513","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels. When separate_channels=false, PyOpenEXR maps each physical channel name through channelNameToRGBA() and coalesces the results into a shared RGB array. A crafted flat scanline EXR that contains both a literal channel such as left and prefixed channels such as left.R, left.G, and left.B causes these names to collide, so the wrapper reuses an undersized two-dimensional NumPy array for the coalesced RGB slices and writes out of bounds when OpenEXR.File(path) decodes the pixels. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"8d210eecb15e0d95","cpes":["cpe:2.3:a:openexr-libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libilmthread:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libilmthread:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libilmthread:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libilmthread","purl":"pkg:apk/alpine/openexr-libilmthread@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIlmThread-3_3.so.32"},{"path":"/usr/lib/libIlmThread-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-68513","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-68513","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68513","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68513","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68513","date":"2026-10-08","epss":0.00194,"percentile":0.08342}],"risk":0.14162,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/c1f3ec0d91cfa5a8035ecd00920835ac76e01640","https://github.com/AcademySoftwareFoundation/openexr/commit/d134e3cd81a2e343f2919e86bf949f576b1ab16a","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-rw5h-3q4v-c3vc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68513","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels. When separate_channels=false, PyOpenEXR maps each physical channel name through channelNameToRGBA() and coalesces the results into a shared RGB array. A crafted flat scanline EXR that contains both a literal channel such as left and prefixed channels such as left.R, left.G, and left.B causes these names to collide, so the wrapper reuses an undersized two-dimensional NumPy array for the coalesced RGB slices and writes out of bounds when OpenEXR.File(path) decodes the pixels. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"60f44bfb88dcfed2","cpes":["cpe:2.3:a:openexr-libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexr:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexr:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexr","purl":"pkg:apk/alpine/openexr-libopenexr@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXR-3_3.so.32"},{"path":"/usr/lib/libOpenEXR-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-68513","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-68513","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68513","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68513","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68513","date":"2026-10-08","epss":0.00194,"percentile":0.08342}],"risk":0.14162,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/c1f3ec0d91cfa5a8035ecd00920835ac76e01640","https://github.com/AcademySoftwareFoundation/openexr/commit/d134e3cd81a2e343f2919e86bf949f576b1ab16a","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-rw5h-3q4v-c3vc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68513","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels. When separate_channels=false, PyOpenEXR maps each physical channel name through channelNameToRGBA() and coalesces the results into a shared RGB array. A crafted flat scanline EXR that contains both a literal channel such as left and prefixed channels such as left.R, left.G, and left.B causes these names to collide, so the wrapper reuses an undersized two-dimensional NumPy array for the coalesced RGB slices and writes out of bounds when OpenEXR.File(path) decodes the pixels. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"ca8c618de871c334","cpes":["cpe:2.3:a:openexr-libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libopenexrcore:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libopenexrcore:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libopenexrcore","purl":"pkg:apk/alpine/openexr-libopenexrcore@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32"},{"path":"/usr/lib/libOpenEXRCore-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-68513","versionConstraint":">= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-68513","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68513","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68513","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68513","date":"2026-10-08","epss":0.00194,"percentile":0.08342}],"risk":0.14162,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/c1f3ec0d91cfa5a8035ecd00920835ac76e01640","https://github.com/AcademySoftwareFoundation/openexr/commit/d134e3cd81a2e343f2919e86bf949f576b1ab16a","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-rw5h-3q4v-c3vc"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68513","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels. When separate_channels=false, PyOpenEXR maps each physical channel name through channelNameToRGBA() and coalesces the results into a shared RGB array. A crafted flat scanline EXR that contains both a literal channel such as left and prefixed channels such as left.R, left.G, and left.B causes these names to collide, so the wrapper reuses an undersized two-dimensional NumPy array for the coalesced RGB slices and writes out of bounds when OpenEXR.File(path) decodes the pixels. This issue is fixed in versions 3.3.13 and 3.4.14."},"relatedVulnerabilities":[]},{"artifact":{"id":"e4fcd4f360f8bc3a","cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg","purl":"pkg:apk/alpine/ffmpeg@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ffmpeg"},{"path":"/usr/bin/ffprobe"},{"path":"/usr/bin/qt-faststart"},{"path":"/usr/share"},{"path":"/usr/share/ffmpeg"},{"path":"/usr/share/ffmpeg/ffprobe.xsd"},{"path":"/usr/share/ffmpeg/libvpx-1080p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-1080p50_60.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-360p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p.ffpreset"},{"path":"/usr/share/ffmpeg/libvpx-720p50_60.ffpreset"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"31aa27a4b60d1742","cpes":["cpe:2.3:a:ffmpeg-libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavcodec:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavcodec:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavcodec:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavcodec","purl":"pkg:apk/alpine/ffmpeg-libavcodec@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavcodec.so.60"},{"path":"/usr/lib/libavcodec.so.60.31.102"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"9b33222d460fcaba","cpes":["cpe:2.3:a:ffmpeg-libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavdevice:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavdevice:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavdevice:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavdevice","purl":"pkg:apk/alpine/ffmpeg-libavdevice@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavdevice.so.60"},{"path":"/usr/lib/libavdevice.so.60.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"e2ce09465cb32a2b","cpes":["cpe:2.3:a:ffmpeg-libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavfilter:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavfilter:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavfilter:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavfilter","purl":"pkg:apk/alpine/ffmpeg-libavfilter@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavfilter.so.9"},{"path":"/usr/lib/libavfilter.so.9.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"576885ad41760160","cpes":["cpe:2.3:a:ffmpeg-libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavformat:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavformat:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavformat:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavformat","purl":"pkg:apk/alpine/ffmpeg-libavformat@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavformat.so.60"},{"path":"/usr/lib/libavformat.so.60.16.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"1bf269246d96ff9b","cpes":["cpe:2.3:a:ffmpeg-libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libavutil:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libavutil:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libavutil:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libavutil","purl":"pkg:apk/alpine/ffmpeg-libavutil@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libavutil.so.58"},{"path":"/usr/lib/libavutil.so.58.29.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"5f3b64aace2a8f3d","cpes":["cpe:2.3:a:ffmpeg-libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libpostproc:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libpostproc:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libpostproc:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libpostproc","purl":"pkg:apk/alpine/ffmpeg-libpostproc@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpostproc.so.57"},{"path":"/usr/lib/libpostproc.so.57.3.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"0adf812a4a07f04d","cpes":["cpe:2.3:a:ffmpeg-libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswresample:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswresample:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswresample:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswresample","purl":"pkg:apk/alpine/ffmpeg-libswresample@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswresample.so.4"},{"path":"/usr/lib/libswresample.so.4.12.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"700422af2a25fe57","cpes":["cpe:2.3:a:ffmpeg-libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg-libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg_libswscale:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg-libswscale:6.1.2-r2:*:*:*:*:*:*:*","cpe:2.3:a:ffmpeg:ffmpeg_libswscale:6.1.2-r2:*:*:*:*:*:*:*"],"name":"ffmpeg-libswscale","purl":"pkg:apk/alpine/ffmpeg-libswscale@6.1.2-r2?arch=x86_64&distro=alpine-3.22.6&upstream=ffmpeg","type":"apk","version":"6.1.2-r2","language":"","licenses":["GPL-2.0-or-later AND LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libswscale.so.7"},{"path":"/usr/lib/libswscale.so.7.5.100"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ffmpeg"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-65705","versionConstraint":">= 3.4, <= 8.1.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:ffmpeg:ffmpeg:6.1.2:*:*:*:*:*:*:*"],"package":{"name":"ffmpeg","version":"6.1.2-r2"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-65705","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-65705","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-65705","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-65705","date":"2026-10-08","epss":0.00187,"percentile":0.0763}],"risk":0.1407175,"urls":["https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c","https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780","https://www.vulncheck.com/advisories/ffmpeg-vf-floodfill-out-of-bounds-write-via-filter-frame"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-65705","description":"FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening."},"relatedVulnerabilities":[]},{"artifact":{"id":"b07bf0871b5a93c7","cpes":["cpe:2.3:a:openexr-libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr-libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr_libiex:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr-libiex:3.3.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:openexr:openexr_libiex:3.3.11-r0:*:*:*:*:*:*:*"],"name":"openexr-libiex","purl":"pkg:apk/alpine/openexr-libiex@3.3.11-r0?arch=x86_64&distro=alpine-3.22.6&upstream=openexr","type":"apk","version":"3.3.11-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libIex-3_3.so.32"},{"path":"/usr/lib/libIex-3_3.so.32.3.3.11"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:093b4a5ccff6e080f1fd0653ed19f05b8a05d8786acf719f61ee1a97de0c8cdb","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openexr"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openexr:openexr:*:*:*:*:*:python:*:*"],"vulnerabilityID":"CVE-2026-68515","versionConstraint":"< 3.2.11||>= 3.3.0, < 3.3.13||>= 3.4.0, < 3.4.14 (python)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openexr:openexr:3.3.11:*:*:*:*:*:*:*"],"package":{"name":"openexr","version":"3.3.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-68515","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68515","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-68515","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-68515","date":"2026-10-08","epss":0.00191,"percentile":0.07991}],"risk":0.13943,"urls":["https://github.com/AcademySoftwareFoundation/openexr/commit/77ee19c021398b1c56f32c3af8347e365dbd4f33","https://github.com/AcademySoftwareFoundation/openexr/commit/c644ac2dfeac82939c81a8551d6f4b7859f63add","https://github.com/AcademySoftwareFoundation/openexr/commit/e2300a3d54a93d20a36a86b82f3a506c4c91476f","https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-gjf7-wjjw-xq56"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68515","description":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14."},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-09T23:31:42.922Z","grype_db_version":"2026-10-09T06:32:32.000Z"}