{"grype_matches":[{"artifact":{"id":"d1631d475c37518a","cpes":["cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u7:*:*:*:*:*:*:*"],"name":"libgnutls30","purl":"pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u7?arch=amd64&distro=debian-12.15&upstream=gnutls28","type":"deb","version":"3.7.9-2+deb12u7","language":"","licenses":["sha256:bb7e5c24b3e27bbba5671dd710d159a0066833bda4caa1d55d8027ffed539337"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libgnutls30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnutls28","version":"3.7.9-2+deb12u7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0-1+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-28757","versionConstraint":"< 2.5.0-1+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-28757","fix":{"state":"fixed","versions":["2.5.0-1+deb12u4"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.5.0-1+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28757","date":"2026-10-08","epss":0.02006,"percentile":0.8022}],"risk":1.5045000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-28757","description":"libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate)."},"relatedVulnerabilities":[{"id":"CVE-2024-28757","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28757","date":"2026-10-08","epss":0.02006,"percentile":0.8022}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/15/1","https://github.com/libexpat/libexpat/issues/839","https://github.com/libexpat/libexpat/pull/842","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/","https://security.netapp.com/advisory/ntap-20240322-0001/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28757","description":"libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate)."}]},{"artifact":{"id":"1e5c5363a73cf859","cpes":["cpe:2.3:a:ldap-utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap-utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"ldap-utils","purl":"pkg:deb/debian/ldap-utils@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ldap-utils/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/ldap-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-2953","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-2953","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2953","date":"2026-10-08","epss":0.0193,"percentile":0.7939}],"risk":1.4475000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-2953","description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function."},"relatedVulnerabilities":[{"id":"CVE-2023-2953","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2953","date":"2026-10-08","epss":0.0193,"percentile":0.7939}],"urls":["http://seclists.org/fulldisclosure/2023/Jul/47","http://seclists.org/fulldisclosure/2023/Jul/48","http://seclists.org/fulldisclosure/2023/Jul/52","https://access.redhat.com/security/cve/CVE-2023-2953","https://bugs.openldap.org/show_bug.cgi?id=9904","https://security.netapp.com/advisory/ntap-20230703-0005/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2953","description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function."}]},{"artifact":{"id":"692b9197d4b21a92","cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"libldap-2.5-0","purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-2953","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-2953","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2953","date":"2026-10-08","epss":0.0193,"percentile":0.7939}],"risk":1.4475000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-2953","description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function."},"relatedVulnerabilities":[{"id":"CVE-2023-2953","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2953","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2953","date":"2026-10-08","epss":0.0193,"percentile":0.7939}],"urls":["http://seclists.org/fulldisclosure/2023/Jul/47","http://seclists.org/fulldisclosure/2023/Jul/48","http://seclists.org/fulldisclosure/2023/Jul/52","https://access.redhat.com/security/cve/CVE-2023-2953","https://bugs.openldap.org/show_bug.cgi?id=9904","https://security.netapp.com/advisory/ntap-20230703-0005/","https://support.apple.com/kb/HT213843","https://support.apple.com/kb/HT213844","https://support.apple.com/kb/HT213845"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2953","description":"A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6110","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-6110","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-08","epss":0.20906,"percentile":0.97507}],"risk":1.0453000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."},"relatedVulnerabilities":[{"id":"CVE-2019-6110","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-08","epss":0.20906,"percentile":0.97507}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf","https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.c","https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c","https://security.gentoo.org/glsa/201903-16","https://security.netapp.com/advisory/ntap-20190213-0001/","https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt","https://www.exploit-db.com/exploits/46193/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0-1+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-59375","versionConstraint":"< 2.5.0-1+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-59375","fix":{"state":"fixed","versions":["2.5.0-1+deb12u4"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.5.0-1+deb12u4"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-59375","date":"2026-10-08","epss":0.01315,"percentile":0.69879}],"risk":0.98625,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59375","description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing."},"relatedVulnerabilities":[{"id":"CVE-2025-59375","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-59375","date":"2026-10-08","epss":0.01315,"percentile":0.69879}],"urls":["https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74","https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes","https://github.com/libexpat/libexpat/issues/1018","https://github.com/libexpat/libexpat/pull/1034","https://issues.oss-fuzz.com/issues/439133977","http://www.openwall.com/lists/oss-security/2025/09/16/2","http://www.openwall.com/lists/oss-security/2026/05/01/5","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59375","description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing."}]},{"artifact":{"id":"9e40126b989ece04","cpes":["cpe:2.3:a:libtasn1-6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1-6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*"],"name":"libtasn1-6","purl":"pkg:deb/debian/libtasn1-6@4.19.0-2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"4.19.0-2+deb12u1","language":"","licenses":["sha256:572ad60ad184d8f52c6dc66d83a61a68f137db560b3452ce00588c9ecf128a65"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtasn1-6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libtasn1-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-13151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libtasn1-6","version":"4.19.0-2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-13151","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"risk":0.8812500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."},"relatedVulnerabilities":[{"id":"CVE-2025-13151","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"urls":["https://gitlab.com/gnutls/libtasn1","https://gitlab.com/gnutls/libtasn1/-/merge_requests/121","http://www.openwall.com/lists/oss-security/2026/01/08/5","https://www.kb.cert.org/vuls/id/271649"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"f6ac26c8e2526776","cpes":["cpe:2.3:a:apache:httpcore5:5.0.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:core5:5.0.2:*:*:*:*:*:*:*"],"name":"httpcore5","purl":"pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2","type":"java-archive","version":"5.0.2","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.httpcomponents.core5","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:org.apache.httpcomponents.core5:httpcore5","manifestName":"","pomArtifactID":"httpcore5","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.4.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hf6x-8p5f-cgmf","versionConstraint":"<5.4.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.httpcomponents.core5:httpcore5","version":"5.0.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hf6x-8p5f-cgmf","fix":{"state":"fixed","versions":["5.4.3"],"available":[{"date":"2026-08-13","kind":"first-observed","version":"5.4.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-54399","https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4","https://github.com/apache/httpcomponents-core/commit/d96a00fec9b2e19f8005e35681df5f6cd6e21a9e","https://github.com/apache/httpcomponents-core/commit/fdc53a32fe0fccf098cc67e71cd125e447c759ed"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hf6x-8p5f-cgmf","description":"Apache HttpComponents Core HTTP/1 header parsing can cause memory-exhaustion denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-54399","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54399","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-54399","date":"2026-10-08","epss":0.0087,"percentile":0.57532}],"urls":["https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy","http://www.openwall.com/lists/oss-security/2026/07/01/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54399","description":"Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length"}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15778","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2020-15778","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-08","epss":0.12996,"percentile":0.96239}],"risk":0.6498,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""},"relatedVulnerabilities":[{"id":"CVE-2020-15778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.6},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-08","epss":0.12996,"percentile":0.96239}],"urls":["https://access.redhat.com/errata/RHSA-2024:3166","https://github.com/cpandya2909/CVE-2020-15778/","https://news.ycombinator.com/item?id=25005567","https://security.gentoo.org/glsa/202212-06","https://security.netapp.com/advisory/ntap-20200731-0007/","https://www.openssh.com/security.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-10524","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10524","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"risk":0.615825,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."},"relatedVulnerabilities":[{"id":"CVE-2024-10524","cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"urls":["https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778","https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/","https://seclists.org/oss-sec/2024/q4/107","http://www.openwall.com/lists/oss-security/2024/11/18/6","https://security.netapp.com/advisory/ntap-20250321-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-31879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2021-31879","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"risk":0.6127199999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."},"relatedVulnerabilities":[{"id":"CVE-2021-31879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"urls":["https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html","https://security.netapp.com/advisory/ntap-20210618-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0-1+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"< 2.5.0-1+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"fixed","versions":["2.5.0-1+deb12u4"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.5.0-1+deb12u4"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"risk":0.60102,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53790","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53790","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53790","cwe":"CWE-78","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53790","cwe":"CWE-88","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53790","date":"2026-10-08","epss":0.00629,"percentile":0.48506}],"risk":0.5723899999999998,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53790","description":"rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user."},"relatedVulnerabilities":[{"id":"CVE-2026-53790","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53790","cwe":"CWE-78","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53790","cwe":"CWE-88","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53790","date":"2026-10-08","epss":0.00629,"percentile":0.48506}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-5hcf-7xxm-rmqq","https://www.vulncheck.com/advisories/rsync-command-injection-via-multiple-code-paths"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53790","description":"rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"45ca0a14113d5717","cpes":["cpe:2.3:a:libncurses6:libncurses6:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses6","purl":"pkg:deb/debian/libncurses6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libncurses6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70461","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70461","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70461","date":"2026-10-08","epss":0.0057,"percentile":0.45415}],"risk":0.46455,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70461","description":"rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-70461","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70461","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70461","date":"2026-10-08","epss":0.0057,"percentile":0.45415}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-jhxm-j4mq-3fj4","https://www.vulncheck.com/advisories/rsync-heap-out-of-bounds-write-via-files-from-entry"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70461","description":"rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70464","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70464","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70464","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70464","date":"2026-10-08","epss":0.00573,"percentile":0.45604}],"risk":0.46412999999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70464","description":"rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients."},"relatedVulnerabilities":[{"id":"CVE-2026-70464","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70464","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70464","date":"2026-10-08","epss":0.00573,"percentile":0.45604}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-hrwq-ccf7-rw5m","https://www.vulncheck.com/advisories/rsync-connection-slot-exhaustion-dos-via-handshake-stall"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70464","description":"rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"2b05e4baf3b202df","cpes":["cpe:2.3:a:apache:log4j-api:2.25.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j_api:2.25.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:log4j:2.25.4:*:*:*:*:*:*:*"],"name":"log4j-api","purl":"pkg:maven/org.apache.logging.log4j/log4j-api@2.25.4","type":"java-archive","version":"2.25.4","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.apache.logging.log4j","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:org.apache.logging.log4j:log4j-api","manifestName":"","pomArtifactID":"log4j-api","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.25.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qv9r-c865-cp47","versionConstraint":">=2.13.1,<2.25.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.logging.log4j:log4j-api","version":"2.25.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qv9r-c865-cp47","fix":{"state":"fixed","versions":["2.25.5"],"available":[{"date":"2026-08-14","kind":"first-observed","version":"2.25.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"risk":0.459345,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-49844","https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844","https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300","https://github.com/apache/logging-log4j2/commit/feadf8eb0b4acb6ddfa4c0ab2bbc6d88b8e12d82","https://github.com/apache/logging-log4j2/releases/tag/rel/2.25.5","https://github.com/apache/logging-log4j2/releases/tag/rel/2.26.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qv9r-c865-cp47","description":"Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization"},"relatedVulnerabilities":[{"id":"CVE-2026-49844","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49844","cwe":"CWE-116","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-49844","date":"2026-10-08","epss":0.00813,"percentile":0.55707}],"urls":["https://github.com/apache/logging-log4j2/pull/4163","https://logging.apache.org/cyclonedx/vdr.xml","https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message","https://logging.apache.org/security.html#CVE-2026-49844"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49844","description":"Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{\"JSON\"}).\n  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70455","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70455","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70455","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70455","date":"2026-10-08","epss":0.00566,"percentile":0.45223}],"risk":0.4584599999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70455","description":"rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources."},"relatedVulnerabilities":[{"id":"CVE-2026-70455","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70455","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70455","date":"2026-10-08","epss":0.00566,"percentile":0.45223}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-rjvj-qgqg-cvx9","https://www.vulncheck.com/advisories/rsync-dos-via-zt-zstandard-compression-thread-exhaustion"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70455","description":"rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53791","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53791","cwe":"CWE-290","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53791","date":"2026-10-08","epss":0.00501,"percentile":0.40971}],"risk":0.45340499999999995,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53791","description":"rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address."},"relatedVulnerabilities":[{"id":"CVE-2026-53791","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53791","cwe":"CWE-290","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53791","date":"2026-10-08","epss":0.00501,"percentile":0.40971}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-h2q9-5fr8-w635","https://www.vulncheck.com/advisories/rsync-daemon-ip-spoofing-via-proxy-protocol-header"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53791","description":"rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.14.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-2768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-2768","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-08","epss":0.08615,"percentile":0.94971}],"risk":0.4307500000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."},"relatedVulnerabilities":[{"id":"CVE-2007-2768","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-08","epss":0.08615,"percentile":0.94971}],"urls":["http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html","http://www.osvdb.org/34601","https://security.netapp.com/advisory/ntap-20191107-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70459","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70459","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70459","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70459","date":"2026-10-08","epss":0.00721,"percentile":0.52523}],"risk":0.42899499999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70459","description":"rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection."},"relatedVulnerabilities":[{"id":"CVE-2026-70459","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70459","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70459","date":"2026-10-08","epss":0.00721,"percentile":0.52523}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-p4v4-qxw9-q72m","https://www.vulncheck.com/advisories/rsync-daemon-crash-via-malformed-file-list-entry"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70459","description":"rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70453","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70453","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70453","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70453","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"risk":0.42525,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70453","description":"rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-70453","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70453","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70453","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-8x5r-mjx8-83hv","https://www.vulncheck.com/advisories/rsync-algorithmic-complexity-dos-via-hash-search"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70453","description":"rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service."}]},{"artifact":{"id":"aa527ab8cb576b14","cpes":["cpe:2.3:a:gzip:gzip:1.12-1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/debian/gzip@1.12-1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.12-1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gzip","version":"1.12-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41992","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"risk":0.42300000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."},"relatedVulnerabilities":[{"id":"CVE-2026-41992","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d","https://www.gnu.org/software/gzip/","http://www.openwall.com/lists/oss-security/2026/08/23/1","http://www.openwall.com/lists/oss-security/2026/08/25/1","http://www.openwall.com/lists/oss-security/2026/08/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70452","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70452","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70452","cwe":"CWE-636","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70452","cwe":"CWE-863","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70452","date":"2026-10-08","epss":0.00462,"percentile":0.38071}],"risk":0.41811,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70452","description":"rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees."},"relatedVulnerabilities":[{"id":"CVE-2026-70452","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70452","cwe":"CWE-636","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70452","cwe":"CWE-863","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70452","date":"2026-10-08","epss":0.00462,"percentile":0.38071}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-6692-28cx-wpqq","https://www.vulncheck.com/advisories/rsync-access-control-bypass-via-dns-resolution-failure"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70452","description":"rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees."}]},{"artifact":{"id":"a27c6b35171bf75d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.17.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70460","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70460","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70460","cwe":"CWE-22","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70460","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70460","date":"2026-10-08","epss":0.00448,"percentile":0.36918}],"risk":0.40767999999999993,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70460","description":"rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent."},"relatedVulnerabilities":[{"id":"CVE-2026-70460","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70460","cwe":"CWE-22","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70460","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70460","date":"2026-10-08","epss":0.00448,"percentile":0.36918}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-w3xf-j2r2-gv4x","https://www.vulncheck.com/advisories/rsync-path-traversal-via-partial-dir-backup-dir-symlink"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70460","description":"rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.14.8","3.15.0rc2"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-02","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-01","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-01","kind":"first-observed","version":"3.13.16"},{"date":"2026-10-01","kind":"first-observed","version":"3.14.8"},{"date":"2026-09-22","kind":"first-observed","version":"3.15.0rc2"},{"date":"2026-09-09","kind":"first-observed","version":"3.15.0rc2"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58469","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58469","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58469","date":"2026-10-08","epss":0.00493,"percentile":0.4041}],"risk":0.39933,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58469","description":"GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior."},"relatedVulnerabilities":[{"id":"CVE-2026-58469","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58469","date":"2026-10-08","epss":0.00493,"percentile":0.4041}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58469","description":"GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.14.8","3.15.0rc3"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-08","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-08","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-08","kind":"first-observed","version":"3.13.16"},{"date":"2026-10-08","kind":"first-observed","version":"3.14.8"},{"date":"2026-10-08","kind":"first-observed","version":"3.15.0rc3"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.11.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"a27c6b35171bf75d","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-core","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0-1+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45186","versionConstraint":"< 2.5.0-1+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-45186","fix":{"state":"fixed","versions":["2.5.0-1+deb12u4"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.5.0-1+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45186","date":"2026-10-08","epss":0.00479,"percentile":0.39397}],"risk":0.35925,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45186","description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input."},"relatedVulnerabilities":[{"id":"CVE-2026-45186","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45186","date":"2026-10-08","epss":0.00479,"percentile":0.39397}],"urls":["https://github.com/libexpat/libexpat/pull/1216","http://www.openwall.com/lists/oss-security/2026/05/11/16","https://access.redhat.com/errata/RHSA-2026:22715","https://access.redhat.com/errata/RHSA-2026:22721","https://access.redhat.com/errata/RHSA-2026:23230","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:27201","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-45186","https://bugzilla.redhat.com/show_bug.cgi?id=2468575","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45186","description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53793","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53793","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53793","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53793","date":"2026-10-08","epss":0.00393,"percentile":0.31359}],"risk":0.35566500000000006,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53793","description":"rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ boundary to gain unauthorized read or write access to files outside the module's subtree."},"relatedVulnerabilities":[{"id":"CVE-2026-53793","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53793","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53793","date":"2026-10-08","epss":0.00393,"percentile":0.31359}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-wj7w-vh23-mm44","https://www.vulncheck.com/advisories/rsync-path-confinement-bypass-via-boundary-marker-in-chroot-mode"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53793","description":"rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ boundary to gain unauthorized read or write access to files outside the module's subtree."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"1e5c5363a73cf859","cpes":["cpe:2.3:a:ldap-utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap-utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"ldap-utils","purl":"pkg:deb/debian/ldap-utils@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ldap-utils/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/ldap-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-17740","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"risk":0.3511,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."},"relatedVulnerabilities":[{"id":"CVE-2017-17740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."}]},{"artifact":{"id":"692b9197d4b21a92","cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"libldap-2.5-0","purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-17740","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"risk":0.3511,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."},"relatedVulnerabilities":[{"id":"CVE-2017-17740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.3488,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-87910","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.15.0a1, < 3.15.0rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-87910","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.15.0a1, < 3.15.0rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.15.0rc3"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-02","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-01","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-01","kind":"first-observed","version":"3.13.16"},{"date":"2026-10-08","kind":"first-observed","version":"3.15.0rc3"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.344005,"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."},"relatedVulnerabilities":[]},{"artifact":{"id":"45ca0a14113d5717","cpes":["cpe:2.3:a:libncurses6:libncurses6:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses6","purl":"pkg:deb/debian/libncurses6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libncurses6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.5.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.0.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6653","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6653","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"risk":0.33370000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."},"relatedVulnerabilities":[{"id":"CVE-2026-6653","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"urls":["https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70462","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70462","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70462","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70462","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70462","date":"2026-10-08","epss":0.00452,"percentile":0.37269}],"risk":0.32996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70462","description":"rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-70462","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70462","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70462","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70462","date":"2026-10-08","epss":0.00452,"percentile":0.37269}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-j9wh-5jmp-2m64","https://www.vulncheck.com/advisories/rsync-signed-integer-overflow-via-msg-io-timeout"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70462","description":"rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0-1+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"< 2.5.0-1+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"fixed","versions":["2.5.0-1+deb12u4"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.5.0-1+deb12u4"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.32642999999999994,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70456","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70456","date":"2026-10-08","epss":0.00396,"percentile":0.31644}],"risk":0.32274,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70456","description":"rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-70456","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70456","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70456","date":"2026-10-08","epss":0.00396,"percentile":0.31644}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-78jc-79jv-v6rw","https://www.vulncheck.com/advisories/rsync-heap-out-of-bounds-write-via-read-args"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70456","description":"rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70458","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70458","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70458","date":"2026-10-08","epss":0.00396,"percentile":0.31644}],"risk":0.32274,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70458","description":"rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data."},"relatedVulnerabilities":[{"id":"CVE-2026-70458","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70458","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70458","date":"2026-10-08","epss":0.00396,"percentile":0.31644}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-gg3m-4m9m-268h","https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-flag-hlinked-handling"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70458","description":"rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"ac2609e96456f774","cpes":["cpe:2.3:a:berriai_project:python-litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriai_project:python_litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriaiproject:python-litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriaiproject:python_litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python-litellm:python-litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python-litellm:python_litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python_litellm:python-litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python_litellm:python_litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriai_project:litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriai:python-litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriai:python_litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriaiproject:litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:litellm:python-litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:litellm:python_litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python-litellm:litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python_litellm:litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python:python-litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python:python_litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:berriai:litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:litellm:litellm:1.85.7:*:*:*:*:*:*:*","cpe:2.3:a:python:litellm:1.85.7:*:*:*:*:*:*:*"],"name":"litellm","purl":"pkg:pypi/litellm@1.85.7","type":"python","version":"1.85.7","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/litellm-1.85.7.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/litellm-1.85.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/litellm-1.85.7.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/litellm-1.85.7.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.88.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3cv6-jpf6-8222","versionConstraint":"<1.88.6 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"litellm","version":"1.85.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-3cv6-jpf6-8222","fix":{"state":"fixed","versions":["1.88.6"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"1.88.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84377","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84377","date":"2026-10-08","epss":0.0054,"percentile":0.43637}],"risk":0.3105,"urls":["https://github.com/BerriAI/litellm/security/advisories/GHSA-3cv6-jpf6-8222","https://nvd.nist.gov/vuln/detail/CVE-2026-84377","https://github.com/BerriAI/litellm/pull/36011","https://github.com/BerriAI/litellm/pull/36314","https://github.com/BerriAI/litellm/pull/36494","https://github.com/BerriAI/litellm/commit/473f72e63a9777d793fbbf57194d8ec4fb97bc1b","https://github.com/BerriAI/litellm/commit/820f247a6abba55cd87d130bef7bba7be3b29d37","https://github.com/BerriAI/litellm/commit/c898d341c02299cf2506d0d8e84cc67953043593"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3cv6-jpf6-8222","description":"LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters"},"relatedVulnerabilities":[{"id":"CVE-2026-84377","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84377","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84377","date":"2026-10-08","epss":0.0054,"percentile":0.43637}],"urls":["https://github.com/BerriAI/litellm/commit/473f72e63a9777d793fbbf57194d8ec4fb97bc1b","https://github.com/BerriAI/litellm/commit/820f247a6abba55cd87d130bef7bba7be3b29d37","https://github.com/BerriAI/litellm/commit/c898d341c02299cf2506d0d8e84cc67953043593","https://github.com/BerriAI/litellm/pull/36011","https://github.com/BerriAI/litellm/pull/36314","https://github.com/BerriAI/litellm/pull/36494","https://github.com/BerriAI/litellm/releases/tag/v1.88.6","https://github.com/BerriAI/litellm/releases/tag/v1.96.2","https://github.com/BerriAI/litellm/security/advisories/GHSA-3cv6-jpf6-8222"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84377","description":"LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did not cover every sensitive parameter or inspect equivalent values across nested request fields, path values, and bracket-notation form data. Routing and credential parameters including api_base, base_url, model_list, fallbacks, and litellm_credential_name could therefore be applied without clearing the operator's stored key, exposing upstream provider credentials and other configured secrets and permitting server-side requests to internal services reachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.14.8","3.15.0rc3"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-08","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-08","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-08","kind":"first-observed","version":"3.13.16"},{"date":"2026-10-08","kind":"first-observed","version":"3.14.8"},{"date":"2026-10-08","kind":"first-observed","version":"3.15.0rc3"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."},"relatedVulnerabilities":[]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53794","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53794","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53794","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53794","date":"2026-10-08","epss":0.00507,"percentile":0.4133}],"risk":0.30166499999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53794","description":"rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-53794","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53794","cwe":"CWE-1284","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53794","date":"2026-10-08","epss":0.00507,"percentile":0.4133}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-p827-vwcp-m964","https://www.vulncheck.com/advisories/rsync-denial-of-service-via-max-alloc-0-logic-error"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53794","description":"rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53783","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53783","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53783","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53783","cwe":"CWE-88","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53783","date":"2026-10-08","epss":0.00374,"percentile":0.2927}],"risk":0.30107,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53783","description":"rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree."},"relatedVulnerabilities":[{"id":"CVE-2026-53783","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53783","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53783","cwe":"CWE-88","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53783","date":"2026-10-08","epss":0.00374,"percentile":0.2927}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-9cgc-64g4-3gv5","https://www.vulncheck.com/advisories/rsync-toctou-race-condition-directory-escape-via-rrsync"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53783","description":"rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"risk":0.2985,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."},"relatedVulnerabilities":[{"id":"CVE-2026-41080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."}]},{"artifact":{"id":"4cab7ef7de016d31","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"372dffabd059479c","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"ca1034d5d24bcf54","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"87d8465053cf56c8","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70457","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70457","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70457","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70457","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70457","date":"2026-10-08","epss":0.00377,"percentile":0.29582}],"risk":0.29594499999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70457","description":"rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory."},"relatedVulnerabilities":[{"id":"CVE-2026-70457","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70457","cwe":"CWE-131","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-70457","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70457","date":"2026-10-08","epss":0.00377,"percentile":0.29582}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-pg7g-xqmr-xpfh","https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-parse-size-arg"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70457","description":"rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-19672","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-19672","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.14.8","3.15.0rc2"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-02","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-02","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-02","kind":"first-observed","version":"3.13.16"},{"date":"2026-10-02","kind":"first-observed","version":"3.14.8"},{"date":"2026-10-02","kind":"first-observed","version":"3.15.0rc2"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.29492999999999997,"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."},"relatedVulnerabilities":[]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70463","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70463","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70463","cwe":"CWE-863","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70463","date":"2026-10-08","epss":0.00364,"percentile":0.28162}],"risk":0.29302,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70463","description":"rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing."},"relatedVulnerabilities":[{"id":"CVE-2026-70463","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70463","cwe":"CWE-863","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70463","date":"2026-10-08","epss":0.00364,"percentile":0.28162}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-pfj8-79vq-xgvr","https://www.vulncheck.com/advisories/rsync-authorization-bypass-via-auth-users-directive-parsing"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70463","description":"rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53795","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53795","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53795","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53795","date":"2026-10-08","epss":0.00396,"percentile":0.31728}],"risk":0.29106,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53795","description":"rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process."},"relatedVulnerabilities":[{"id":"CVE-2026-53795","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53795","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53795","date":"2026-10-08","epss":0.00396,"percentile":0.31728}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-m9vj-637x-v6pq","https://www.vulncheck.com/advisories/rsync-arbitrary-file-write-via-temp-dir-link-dest"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53795","description":"rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-3234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2008-3234","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-08","epss":0.05773,"percentile":0.92898}],"risk":0.28865,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."},"relatedVulnerabilities":[{"id":"CVE-2008-3234","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-08","epss":0.05773,"percentile":0.92898}],"urls":["http://www.securityfocus.com/bid/30276","https://exchange.xforce.ibmcloud.com/vulnerabilities/44037","https://www.exploit-db.com/exploits/6094"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58471","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"risk":0.28469999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58471","description":"GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response."},"relatedVulnerabilities":[{"id":"CVE-2026-58471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58471","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58471","description":"GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58472","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58472","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58472","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"risk":0.28469999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58472","description":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase."},"relatedVulnerabilities":[{"id":"CVE-2026-58472","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58472","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58472","description":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase."}]},{"artifact":{"id":"077923f667034501","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","type":"deb","version":"1:1.2.13.dfsg-1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53789","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53789","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53789","cwe":"CWE-807","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53789","date":"2026-10-08","epss":0.00357,"percentile":0.27404}],"risk":0.27846,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53789","description":"rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory."},"relatedVulnerabilities":[{"id":"CVE-2026-53789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53789","cwe":"CWE-807","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53789","date":"2026-10-08","epss":0.00357,"percentile":0.27404}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-fxwg-7hmf-xh5q","https://www.vulncheck.com/advisories/rsync-arbitrary-file-deletion-via-malicious-file-list"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53789","description":"rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"58c10ea7ffbc22a3","cpes":["cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"gcc-12-base","purl":"pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/gcc-12-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"9454a77b5ea4561d","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"c2f4fec51904a8ce","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53801","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53801","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53801","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53801","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53801","date":"2026-10-08","epss":0.00349,"percentile":0.26488}],"risk":0.27396499999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53801","description":"rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree. Attackers who can create or manipulate symlinks in a path component of the scanned tree can replace a symlink with a directory entry pointing outside the module root between the lstat() call and the subsequent opendir() call, exposing files beyond the intended root in both daemon-mode and non-daemon sender-side scanning."},"relatedVulnerabilities":[{"id":"CVE-2026-53801","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53801","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53801","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53801","date":"2026-10-08","epss":0.00349,"percentile":0.26488}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-mch3-qr4p-chgm","https://www.vulncheck.com/advisories/rsync-symlink-race-condition-directory-traversal"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53801","description":"rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree. Attackers who can create or manipulate symlinks in a path component of the scanned tree can replace a symlink with a directory entry pointing outside the module root between the lstat() call and the subsequent opendir() call, exposing files beyond the intended root in both daemon-mode and non-daemon sender-side scanning."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.8.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2016-20012","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-08","epss":0.05326,"percentile":0.92406}],"risk":0.26630000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"},"relatedVulnerabilities":[{"id":"CVE-2016-20012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-08","epss":0.05326,"percentile":0.92406}],"urls":["https://github.com/openssh/openssh-portable/blob/d0fffc88c8fe90c1815c6f4097bc8cbcabc0f3dd/auth2-pubkey.c#L261-L265","https://github.com/openssh/openssh-portable/pull/270","https://github.com/openssh/openssh-portable/pull/270#issuecomment-920577097","https://github.com/openssh/openssh-portable/pull/270#issuecomment-943909185","https://rushter.com/blog/public-ssh-keys/","https://security.netapp.com/advisory/ntap-20211014-0005/","https://utcc.utoronto.ca/~cks/space/blog/tech/SSHKeysAreInfoLeak","https://www.openwall.com/lists/oss-security/2018/08/24/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"1e5c5363a73cf859","cpes":["cpe:2.3:a:ldap-utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap-utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"ldap-utils","purl":"pkg:deb/debian/ldap-utils@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ldap-utils/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/ldap-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2015-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"risk":0.26345,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."},"relatedVulnerabilities":[{"id":"CVE-2015-3276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."}]},{"artifact":{"id":"692b9197d4b21a92","cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"libldap-2.5-0","purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2015-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"risk":0.26345,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."},"relatedVulnerabilities":[{"id":"CVE-2015-3276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.14.8","3.15.0rc2"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-02","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-01","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-01","kind":"first-observed","version":"3.13.16"},{"date":"2026-10-01","kind":"first-observed","version":"3.14.8"},{"date":"2026-09-22","kind":"first-observed","version":"3.15.0rc2"},{"date":"2026-09-09","kind":"first-observed","version":"3.15.0rc2"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53798","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53798","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53798","cwe":"CWE-704","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53798","date":"2026-10-08","epss":0.00428,"percentile":0.35069}],"risk":0.25466,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53798","description":"rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files."},"relatedVulnerabilities":[{"id":"CVE-2026-53798","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53798","cwe":"CWE-704","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53798","date":"2026-10-08","epss":0.00428,"percentile":0.35069}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-hx7p-3gvv-pqgv","https://www.vulncheck.com/advisories/rsync-privilege-confusion-via-name-converter-uid-gid-mapping"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53798","description":"rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"f3e6debe9866c7e0","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vxq7-64xx-v4gw","versionConstraint":">=1.10.3,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-vxq7-64xx-v4gw","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"risk":0.23944000000000001,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw","https://nvd.nist.gov/vuln/detail/CVE-2026-97689","https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vxq7-64xx-v4gw","description":"urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory"},"relatedVulnerabilities":[{"id":"CVE-2026-97689","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"urls":["https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97689","description":"urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53786","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53786","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53786","cwe":"CWE-863","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53786","date":"2026-10-08","epss":0.00398,"percentile":0.31911}],"risk":0.23680999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53786","description":"rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to introduce rules that supersede daemon module-level restrictions, gaining access to files the module filter was intended to exclude."},"relatedVulnerabilities":[{"id":"CVE-2026-53786","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53786","cwe":"CWE-863","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53786","date":"2026-10-08","epss":0.00398,"percentile":0.31911}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-mrc3-6cwx-hch6","https://www.vulncheck.com/advisories/rsync-filter-rule-bypass-via-filter-merge-directive"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53786","description":"rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to introduce rules that supersede daemon module-level restrictions, gaining access to files the module filter was intended to exclude."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.2352,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."},"relatedVulnerabilities":[{"id":"CVE-2026-11822","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."}]},{"artifact":{"id":"d08ba720d5534ad4","cpes":["cpe:2.3:a:sqlite3:sqlite3:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"sqlite3","purl":"pkg:deb/debian/sqlite3@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sqlite3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/sqlite3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.2352,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."},"relatedVulnerabilities":[{"id":"CVE-2026-11822","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42767","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42767","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"risk":0.23217000000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42767","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42767","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42767","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"risk":0.23217000000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42767","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"6a0cb0d66b61301c","cpes":["cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey_project:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey_project:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<heyproject:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<heyproject:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey_project:uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral-software-inc-\\\"-\\<hey:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral-software-inc-\\\"-\\<hey:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<heyproject:uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral-software-inc-\\\"-\\<hey:uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey:uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python-uv:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python-uv:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python_uv:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python_uv:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python-uv:uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python_uv:uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:uv:python-uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:uv:python_uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:python:uv:0.12.10:*:*:*:*:*:*:*","cpe:2.3:a:uv:uv:0.12.10:*:*:*:*:*:*:*"],"name":"uv","purl":"pkg:pypi/uv@0.12.10","type":"python","version":"0.12.10","language":"python","licenses":["MIT OR Apache-2.0"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/uv-0.12.10.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/uv-0.12.10.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/uv-0.12.10.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/uv-0.12.10.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.12.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2cv4-cqwr-gwf7","versionConstraint":">=0.12.7,<0.12.18 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"uv","version":"0.12.10"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-2cv4-cqwr-gwf7","fix":{"state":"fixed","versions":["0.12.18"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"0.12.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"risk":0.23217000000000004,"urls":["https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","https://nvd.nist.gov/vuln/detail/CVE-2026-104843","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/releases/tag/0.12.18"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2cv4-cqwr-gwf7","description":"uv: Path traversal on Windows through wheel extraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104843","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"urls":["https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/releases/tag/0.12.18","https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843","description":"uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18."}]},{"artifact":{"id":"de09852bf5446fb5","cpes":["cpe:2.3:a:uv_project:uv:0.12.10:*:*:*:*:rust:*:*","cpe:2.3:a:uv:uv:0.12.10:*:*:*:*:rust:*:*"],"name":"uv","purl":"pkg:cargo/uv@0.12.10","type":"rust-crate","version":"0.12.10","language":"rust","licenses":[],"locations":[{"path":"/home/airflow/.local/bin/uv","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/bin/uv","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.12.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2cv4-cqwr-gwf7","versionConstraint":">=0.12.7,<0.12.18 (unknown)"},"matcher":"rust-matcher","searchedBy":{"package":{"name":"uv","version":"0.12.10"},"language":"rust","namespace":"github:language:rust"}}],"vulnerability":{"id":"GHSA-2cv4-cqwr-gwf7","fix":{"state":"fixed","versions":["0.12.18"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"0.12.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"risk":0.23217000000000004,"urls":["https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","https://nvd.nist.gov/vuln/detail/CVE-2026-104843","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/releases/tag/0.12.18"],"severity":"Medium","namespace":"github:language:rust","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2cv4-cqwr-gwf7","description":"uv: Path traversal on Windows through wheel extraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104843","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"urls":["https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/releases/tag/0.12.18","https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843","description":"uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18."}]},{"artifact":{"id":"bcd234bddcb70ce8","cpes":["cpe:2.3:a:uv_project:uv:0.12.10:*:*:*:*:rust:*:*","cpe:2.3:a:uv:uv:0.12.10:*:*:*:*:rust:*:*"],"name":"uv","purl":"pkg:cargo/uv@0.12.10","type":"rust-crate","version":"0.12.10","language":"rust","licenses":[],"locations":[{"path":"/home/airflow/.local/bin/uvx","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/bin/uvx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.12.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2cv4-cqwr-gwf7","versionConstraint":">=0.12.7,<0.12.18 (unknown)"},"matcher":"rust-matcher","searchedBy":{"package":{"name":"uv","version":"0.12.10"},"language":"rust","namespace":"github:language:rust"}}],"vulnerability":{"id":"GHSA-2cv4-cqwr-gwf7","fix":{"state":"fixed","versions":["0.12.18"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"0.12.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"risk":0.23217000000000004,"urls":["https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","https://nvd.nist.gov/vuln/detail/CVE-2026-104843","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/releases/tag/0.12.18"],"severity":"Medium","namespace":"github:language:rust","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2cv4-cqwr-gwf7","description":"uv: Path traversal on Windows through wheel extraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104843","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"urls":["https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/releases/tag/0.12.18","https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843","description":"uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18."}]},{"artifact":{"id":"5b92f96bb2bc7598","cpes":["cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey_project:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey_project:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<heyproject:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<heyproject:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey_project:uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral-software-inc-\\\"-\\<hey:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral-software-inc-\\\"-\\<hey:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<heyproject:uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral-software-inc-\\\"-\\<hey:uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:\\\"astral_software_inc_\\\"_\\<hey:uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python-uv:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python-uv:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python_uv:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python_uv:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python-uv:uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python_uv:uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:uv:python-uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:uv:python_uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:python:uv:0.12.15:*:*:*:*:*:*:*","cpe:2.3:a:uv:uv:0.12.15:*:*:*:*:*:*:*"],"name":"uv","purl":"pkg:pypi/uv@0.12.15","type":"python","version":"0.12.15","language":"python","licenses":["MIT OR Apache-2.0"],"locations":[{"path":"/home/airflow/.local/share/uv/tools/prek/lib/python3.13/site-packages/uv-0.12.15.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/share/uv/tools/prek/lib/python3.13/site-packages/uv-0.12.15.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/share/uv/tools/prek/lib/python3.13/site-packages/uv-0.12.15.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/share/uv/tools/prek/lib/python3.13/site-packages/uv-0.12.15.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.12.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2cv4-cqwr-gwf7","versionConstraint":">=0.12.7,<0.12.18 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"uv","version":"0.12.15"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-2cv4-cqwr-gwf7","fix":{"state":"fixed","versions":["0.12.18"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"0.12.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"risk":0.23217000000000004,"urls":["https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","https://nvd.nist.gov/vuln/detail/CVE-2026-104843","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/releases/tag/0.12.18"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2cv4-cqwr-gwf7","description":"uv: Path traversal on Windows through wheel extraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104843","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"urls":["https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/releases/tag/0.12.18","https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843","description":"uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18."}]},{"artifact":{"id":"18d2950a12e27f7c","cpes":["cpe:2.3:a:uv_project:uv:0.12.15:*:*:*:*:rust:*:*","cpe:2.3:a:uv:uv:0.12.15:*:*:*:*:rust:*:*"],"name":"uv","purl":"pkg:cargo/uv@0.12.15","type":"rust-crate","version":"0.12.15","language":"rust","licenses":[],"locations":[{"path":"/home/airflow/.local/share/uv/tools/prek/bin/uv","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/share/uv/tools/prek/bin/uv","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.12.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2cv4-cqwr-gwf7","versionConstraint":">=0.12.7,<0.12.18 (unknown)"},"matcher":"rust-matcher","searchedBy":{"package":{"name":"uv","version":"0.12.15"},"language":"rust","namespace":"github:language:rust"}}],"vulnerability":{"id":"GHSA-2cv4-cqwr-gwf7","fix":{"state":"fixed","versions":["0.12.18"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"0.12.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"risk":0.23217000000000004,"urls":["https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","https://nvd.nist.gov/vuln/detail/CVE-2026-104843","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/releases/tag/0.12.18"],"severity":"Medium","namespace":"github:language:rust","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2cv4-cqwr-gwf7","description":"uv: Path traversal on Windows through wheel extraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104843","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"urls":["https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/releases/tag/0.12.18","https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843","description":"uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18."}]},{"artifact":{"id":"290d4b6584d48287","cpes":["cpe:2.3:a:uv_project:uv:0.12.15:*:*:*:*:rust:*:*","cpe:2.3:a:uv:uv:0.12.15:*:*:*:*:rust:*:*"],"name":"uv","purl":"pkg:cargo/uv@0.12.15","type":"rust-crate","version":"0.12.15","language":"rust","licenses":[],"locations":[{"path":"/home/airflow/.local/share/uv/tools/prek/bin/uvx","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/share/uv/tools/prek/bin/uvx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.12.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2cv4-cqwr-gwf7","versionConstraint":">=0.12.7,<0.12.18 (unknown)"},"matcher":"rust-matcher","searchedBy":{"package":{"name":"uv","version":"0.12.15"},"language":"rust","namespace":"github:language:rust"}}],"vulnerability":{"id":"GHSA-2cv4-cqwr-gwf7","fix":{"state":"fixed","versions":["0.12.18"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"0.12.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"risk":0.23217000000000004,"urls":["https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","https://nvd.nist.gov/vuln/detail/CVE-2026-104843","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/releases/tag/0.12.18"],"severity":"Medium","namespace":"github:language:rust","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2cv4-cqwr-gwf7","description":"uv: Path traversal on Windows through wheel extraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104843","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104843","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104843","date":"2026-10-08","epss":0.00426,"percentile":0.34827}],"urls":["https://github.com/astral-sh/uv/commit/67169645278ce082638d619beefa6d062540843b","https://github.com/astral-sh/uv/pull/21923","https://github.com/astral-sh/uv/releases/tag/0.12.18","https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104843","description":"uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected. This issue is fixed in version 0.12.18."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.8.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"risk":0.228145,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties"},"relatedVulnerabilities":[{"id":"CVE-2026-54515","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53792","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53792","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53792","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53792","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53792","date":"2026-10-08","epss":0.00311,"percentile":0.2193}],"risk":0.22702999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53792","description":"rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side."},"relatedVulnerabilities":[{"id":"CVE-2026-53792","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53792","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53792","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53792","date":"2026-10-08","epss":0.00311,"percentile":0.2193}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-cg57-rp9g-56hw","https://www.vulncheck.com/advisories/rsync-out-of-bounds-read-via-zero-length-checksum-block"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53792","description":"rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5gvw-p9qm-jgwh","versionConstraint":">=2.18.0,<=2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5gvw-p9qm-jgwh","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59889","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59889","date":"2026-10-08","epss":0.00389,"percentile":0.30837}],"risk":0.22367499999999996,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh","https://nvd.nist.gov/vuln/detail/CVE-2026-59889","https://github.com/FasterXML/jackson-databind/issues/6060","https://github.com/FasterXML/jackson-databind/pull/6056","https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5gvw-p9qm-jgwh","description":"jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-59889","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59889","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59889","date":"2026-10-08","epss":0.00389,"percentile":0.30837}],"urls":["https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b","https://github.com/FasterXML/jackson-databind/issues/6060","https://github.com/FasterXML/jackson-databind/pull/6056","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59889","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"6eae50b8c6e3da28","cpes":["cpe:2.3:a:libmariadb3:libmariadb3:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3","purl":"pkg:deb/debian/libmariadb3@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"a366b52f20cc78cd","cpes":["cpe:2.3:a:libmariadb3-compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3-compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3-compat","purl":"pkg:deb/debian/libmariadb3-compat@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3-compat/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3-compat/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"701b2e8ceba5d6be","cpes":["cpe:2.3:a:mariadb-client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client","purl":"pkg:deb/debian/mariadb-client@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.list"},{"path":"/var/lib/dpkg/info/mariadb-client.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postinst"},{"path":"/var/lib/dpkg/info/mariadb-client.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"b3cea487453c889f","cpes":["cpe:2.3:a:mariadb-client-core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client-core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client-core","purl":"pkg:deb/debian/mariadb-client-core@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client-core/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client-core/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"32abad22b22e448d","cpes":["cpe:2.3:a:mariadb-common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-common","purl":"pkg:deb/debian/mariadb-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.list"},{"path":"/var/lib/dpkg/info/mariadb-common.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postinst"},{"path":"/var/lib/dpkg/info/mariadb-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"de3ea55f6de1cad3","cpes":["cpe:2.3:a:mysql-common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql-common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mysql-common","purl":"pkg:deb/debian/mysql-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mysql-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mysql-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.list"},{"path":"/var/lib/dpkg/info/mysql-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-47023","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"risk":0.22274999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-47023","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47023","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-47023","date":"2026-10-08","epss":0.0045,"percentile":0.37093}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47023","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"6eae50b8c6e3da28","cpes":["cpe:2.3:a:libmariadb3:libmariadb3:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3","purl":"pkg:deb/debian/libmariadb3@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"risk":0.21749999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60585","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"a366b52f20cc78cd","cpes":["cpe:2.3:a:libmariadb3-compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3-compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3-compat","purl":"pkg:deb/debian/libmariadb3-compat@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3-compat/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3-compat/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"risk":0.21749999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60585","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"701b2e8ceba5d6be","cpes":["cpe:2.3:a:mariadb-client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client","purl":"pkg:deb/debian/mariadb-client@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.list"},{"path":"/var/lib/dpkg/info/mariadb-client.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postinst"},{"path":"/var/lib/dpkg/info/mariadb-client.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"risk":0.21749999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60585","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"b3cea487453c889f","cpes":["cpe:2.3:a:mariadb-client-core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client-core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client-core","purl":"pkg:deb/debian/mariadb-client-core@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client-core/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client-core/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"risk":0.21749999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60585","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"32abad22b22e448d","cpes":["cpe:2.3:a:mariadb-common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-common","purl":"pkg:deb/debian/mariadb-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.list"},{"path":"/var/lib/dpkg/info/mariadb-common.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postinst"},{"path":"/var/lib/dpkg/info/mariadb-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"risk":0.21749999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60585","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"de3ea55f6de1cad3","cpes":["cpe:2.3:a:mysql-common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql-common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mysql-common","purl":"pkg:deb/debian/mysql-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mysql-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mysql-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.list"},{"path":"/var/lib/dpkg/info/mysql-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"risk":0.21749999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60585","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.6,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60585","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60585","date":"2026-10-08","epss":0.00375,"percentile":0.29419}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60585","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-7458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-7458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7458","date":"2026-10-08","epss":0.00237,"percentile":0.13523}],"risk":0.21448500000000004,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7458","description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause."},"relatedVulnerabilities":[{"id":"CVE-2025-7458","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7458","date":"2026-10-08","epss":0.00237,"percentile":0.13523}],"urls":["https://sqlite.org/forum/forumpost/16ce2bb7a639e29b","https://sqlite.org/src/info/12ad822d9b827777"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7458","description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause."}]},{"artifact":{"id":"d08ba720d5534ad4","cpes":["cpe:2.3:a:sqlite3:sqlite3:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"sqlite3","purl":"pkg:deb/debian/sqlite3@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sqlite3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/sqlite3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-7458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-7458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7458","date":"2026-10-08","epss":0.00237,"percentile":0.13523}],"risk":0.21448500000000004,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7458","description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause."},"relatedVulnerabilities":[{"id":"CVE-2025-7458","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7458","date":"2026-10-08","epss":0.00237,"percentile":0.13523}],"urls":["https://sqlite.org/forum/forumpost/16ce2bb7a639e29b","https://sqlite.org/src/info/12ad822d9b827777"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7458","description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"f8ad3f5238dbcf6a","cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.34+dfsg-1.2+deb12u1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"risk":0.210525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-7709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-7709","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7709","date":"2026-10-08","epss":0.00353,"percentile":0.26886}],"risk":0.210035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7709","description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds."},"relatedVulnerabilities":[{"id":"CVE-2025-7709","cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7709","date":"2026-10-08","epss":0.00353,"percentile":0.26886}],"urls":["https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g","http://www.openwall.com/lists/oss-security/2025/09/06/2","http://www.openwall.com/lists/oss-security/2025/11/18/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7709","description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds."}]},{"artifact":{"id":"d08ba720d5534ad4","cpes":["cpe:2.3:a:sqlite3:sqlite3:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"sqlite3","purl":"pkg:deb/debian/sqlite3@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sqlite3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/sqlite3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-7709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-7709","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7709","date":"2026-10-08","epss":0.00353,"percentile":0.26886}],"risk":0.210035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7709","description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds."},"relatedVulnerabilities":[{"id":"CVE-2025-7709","cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7709","date":"2026-10-08","epss":0.00353,"percentile":0.26886}],"urls":["https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g","http://www.openwall.com/lists/oss-security/2025/09/06/2","http://www.openwall.com/lists/oss-security/2025/11/18/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7709","description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22-1~deb12u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.0.22-1~deb12u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.0.22-1~deb12u1"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"3.0.22-1~deb12u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"08a3557482f12ea3","cpes":["cpe:2.3:a:python-werkzeug:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python-werkzeug:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python_werkzeug:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python_werkzeug:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python-werkzeug:werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python_werkzeug:werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:werkzeug:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:werkzeug:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python:python-werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python:python_werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:werkzeug:werkzeug:3.1.8:*:*:*:*:*:*:*","cpe:2.3:a:python:werkzeug:3.1.8:*:*:*:*:*:*:*"],"name":"werkzeug","purl":"pkg:pypi/werkzeug@3.1.8","type":"python","version":"3.1.8","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/werkzeug-3.1.8.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/werkzeug-3.1.8.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/werkzeug-3.1.8.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/werkzeug-3.1.8.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.1.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g6x2-hccm-hh4m","versionConstraint":"<3.1.9 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"werkzeug","version":"3.1.8"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-g6x2-hccm-hh4m","fix":{"state":"fixed","versions":["3.1.9"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"3.1.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102598","cwe":"CWE-67","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102598","date":"2026-10-08","epss":0.00368,"percentile":0.28622}],"risk":0.20792,"urls":["https://github.com/pallets/werkzeug/security/advisories/GHSA-g6x2-hccm-hh4m","https://nvd.nist.gov/vuln/detail/CVE-2026-102598","https://github.com/pallets/werkzeug/pull/3309","https://github.com/pallets/werkzeug/commit/8d77320bcdf3a34941ec06dcf16b03c065cd21b6","https://github.com/pallets/werkzeug/releases/tag/3.1.9"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g6x2-hccm-hh4m","description":"Werkzeug safe_join() allows Windows special device names"},"relatedVulnerabilities":[{"id":"CVE-2026-102598","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102598","cwe":"CWE-67","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102598","date":"2026-10-08","epss":0.00368,"percentile":0.28622}],"urls":["https://github.com/pallets/werkzeug/commit/8d77320bcdf3a34941ec06dcf16b03c065cd21b6","https://github.com/pallets/werkzeug/pull/3309","https://github.com/pallets/werkzeug/releases/tag/3.1.9","https://github.com/pallets/werkzeug/security/advisories/GHSA-g6x2-hccm-hh4m"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102598","description":"Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"a921e2ccd2226c8c","cpes":["cpe:2.3:a:mike_bayer_\\<mike_project:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mike_project:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mikeproject:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mikeproject:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mike_project:mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike-bayer-\\<mike:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike-bayer-\\<mike:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mike:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mike:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mikeproject:mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python-mako:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python-mako:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python_mako:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python_mako:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike-bayer-\\<mike:mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mike_bayer_\\<mike:mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mako:python-mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mako:python_mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python-mako:mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python_mako:mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:python:mako:1.4.1:*:*:*:*:*:*:*","cpe:2.3:a:mako:mako:1.4.1:*:*:*:*:*:*:*"],"name":"mako","purl":"pkg:pypi/mako@1.4.1","type":"python","version":"1.4.1","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/mako-1.4.1.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/mako-1.4.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/mako-1.4.1.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/mako-1.4.1.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/mako-1.4.1.dist-info/top_level.txt","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/mako-1.4.1.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.4.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5639-2j2p-m4mx","versionConstraint":"<=1.4.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"mako","version":"1.4.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-5639-2j2p-m4mx","fix":{"state":"fixed","versions":["1.4.2"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.4.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102991","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102991","date":"2026-10-08","epss":0.00356,"percentile":0.27232}],"risk":0.20469999999999997,"urls":["https://github.com/sqlalchemy/mako/security/advisories/GHSA-5639-2j2p-m4mx","https://nvd.nist.gov/vuln/detail/CVE-2026-102991","https://github.com/sqlalchemy/mako/issues/441","https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08","https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5639-2j2p-m4mx","description":"Mako: Path traversal via drive-letter URI on Windows in TemplateLookup"},"relatedVulnerabilities":[{"id":"CVE-2026-102991","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102991","cwe":"CWE-22","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102991","date":"2026-10-08","epss":0.00356,"percentile":0.27232}],"urls":["https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08","https://github.com/sqlalchemy/mako/issues/441","https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2","https://github.com/sqlalchemy/mako/security/advisories/GHSA-5639-2j2p-m4mx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102991","description":"Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.15.0a6"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 3.15.0a6 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.15.0a6"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 3.15.0a6 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"fixed","versions":["3.15.0a6"],"available":[{"date":"2026-09-22","kind":"first-observed","version":"3.15.0a6"},{"date":"2026-03-03","kind":"first-observed","version":"3.15.0a6"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.20110500000000003,"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."},"relatedVulnerabilities":[]},{"artifact":{"id":"f8ad3f5238dbcf6a","cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.34+dfsg-1.2+deb12u1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"risk":0.1996,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"risk":0.195655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted."},"relatedVulnerabilities":[{"id":"CVE-2026-4873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"risk":0.195655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted."},"relatedVulnerabilities":[{"id":"CVE-2026-4873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"risk":0.195655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted."},"relatedVulnerabilities":[{"id":"CVE-2026-4873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.18966000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53784","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53784","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53784","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53784","date":"2026-10-08","epss":0.00238,"percentile":0.13613}],"risk":0.18921000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53784","description":"rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access."},"relatedVulnerabilities":[{"id":"CVE-2026-53784","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53784","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53784","date":"2026-10-08","epss":0.00238,"percentile":0.13613}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-ffg2-fr5g-3rxw","https://www.vulncheck.com/advisories/rsync-path-traversal-via-symlink-module-root"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53784","description":"rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53802","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53802","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53802","cwe":"CWE-61","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53802","date":"2026-10-08","epss":0.00238,"percentile":0.13613}],"risk":0.18921000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53802","description":"rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process."},"relatedVulnerabilities":[{"id":"CVE-2026-53802","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53802","cwe":"CWE-61","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53802","date":"2026-10-08","epss":0.00238,"percentile":0.13613}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4","https://www.vulncheck.com/advisories/rsync-arbitrary-file-read-via-symlink-following"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53802","description":"rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process."}]},{"artifact":{"id":"3313f8cd2918cd33","cpes":["cpe:2.3:a:jose_padilla_\\<hello_project:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<hello_project:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<helloproject:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<helloproject:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<hello_project:pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose-padilla-\\<hello:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose-padilla-\\<hello:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<hello:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<hello:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<helloproject:pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose-padilla-\\<hello:pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:jose_padilla_\\<hello:pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python-pyjwt:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python-pyjwt:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python_pyjwt:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python_pyjwt:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:pyjwt:python-pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:pyjwt:python_pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python-pyjwt:pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python_pyjwt:pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:python:pyjwt:2.14.0:*:*:*:*:*:*:*","cpe:2.3:a:pyjwt:pyjwt:2.14.0:*:*:*:*:*:*:*"],"name":"pyjwt","purl":"pkg:pypi/pyjwt@2.14.0","type":"python","version":"2.14.0","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/pyjwt-2.14.0.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/pyjwt-2.14.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/pyjwt-2.14.0.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/pyjwt-2.14.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/pyjwt-2.14.0.dist-info/top_level.txt","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/pyjwt-2.14.0.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.15.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-42vr-xj54-vc7v","versionConstraint":">=2.0.0a1,<=2.14.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pyjwt","version":"2.14.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-42vr-xj54-vc7v","fix":{"state":"fixed","versions":["2.15.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.15.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101918","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101918","date":"2026-10-08","epss":0.00358,"percentile":0.27501}],"risk":0.18437,"urls":["https://github.com/jpadilla/pyjwt/security/advisories/GHSA-42vr-xj54-vc7v","https://nvd.nist.gov/vuln/detail/CVE-2026-101918","https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b","https://github.com/jpadilla/pyjwt/releases/tag/2.15.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-42vr-xj54-vc7v","description":"PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)"},"relatedVulnerabilities":[{"id":"CVE-2026-101918","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101918","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101918","date":"2026-10-08","epss":0.00358,"percentile":0.27501}],"urls":["https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b","https://github.com/jpadilla/pyjwt/releases/tag/2.15.0","https://github.com/jpadilla/pyjwt/security/advisories/GHSA-42vr-xj54-vc7v"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101918","description":"PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload reaches json.loads. As a result, documented PyJWT exception handling does not contain the failure. Consequently, an unauthenticated request can raise an exception that may produce an HTTP 500 response. The advisory-defined affected implementation also includes jwt/api_jwt.py, verify_signature=False. This issue is fixed in version 2.15.0."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53803","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53803","date":"2026-10-08","epss":0.00229,"percentile":0.12621}],"risk":0.1832,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53803","description":"rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations."},"relatedVulnerabilities":[{"id":"CVE-2026-53803","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53803","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53803","date":"2026-10-08","epss":0.00229,"percentile":0.12621}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-g9f4-7q66-9582","https://www.vulncheck.com/advisories/rsync-symlink-following-arbitrary-file-overwrite"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53803","description":"rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations."}]},{"artifact":{"id":"f3e6debe9866c7e0","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8988-9cw3-xx77","versionConstraint":">=1.26.0,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-8988-9cw3-xx77","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"risk":0.18270999999999998,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77","https://nvd.nist.gov/vuln/detail/CVE-2026-97687","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8988-9cw3-xx77","description":"urllib3: HTTPS proxy TLS configuration may be ignored or overridden"},"relatedVulnerabilities":[{"id":"CVE-2026-97687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"urls":["https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97687","description":"urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"58c10ea7ffbc22a3","cpes":["cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"gcc-12-base","purl":"pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/gcc-12-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"9454a77b5ea4561d","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"c2f4fec51904a8ce","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"b906ffcf4bbc48dd","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.52.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/debian/libnghttp2-14@1.52.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=nghttp2","type":"deb","version":"1.52.0-1+deb12u3","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"nghttp2","version":"1.52.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-58055","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."}]},{"artifact":{"id":"25efd5aa65ab55cb","cpes":["cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-2:libsasl2_2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2-2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2_2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_2:2.1.28\\+dfsg-10:*:*:*:*:*:*:*"],"name":"libsasl2-2","purl":"pkg:deb/debian/libsasl2-2@2.1.28%2Bdfsg-10?arch=amd64&distro=debian-12.15&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg-10","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause","BSD-4-clause-KTH","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","OpenSSL","RSA-MD","SSLeay"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libsasl2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg-10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"db067f1aa4046cd6","cpes":["cpe:2.3:a:libsasl2-modules:libsasl2-modules:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules:2.1.28\\+dfsg-10:*:*:*:*:*:*:*"],"name":"libsasl2-modules","purl":"pkg:deb/debian/libsasl2-modules@2.1.28%2Bdfsg-10?arch=amd64&distro=debian-12.15&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg-10","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause","BSD-4-clause-KTH","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","OpenSSL","RSA-MD","SSLeay"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libsasl2-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libsasl2-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg-10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"4f1c60756841024e","cpes":["cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules-db:libsasl2_modules_db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2-modules-db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2_modules_db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2-modules-db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules_db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules-db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules_db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules-db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules_db:2.1.28\\+dfsg-10:*:*:*:*:*:*:*"],"name":"libsasl2-modules-db","purl":"pkg:deb/debian/libsasl2-modules-db@2.1.28%2Bdfsg-10?arch=amd64&distro=debian-12.15&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg-10","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause","BSD-4-clause-KTH","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","OpenSSL","RSA-MD","SSLeay"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules-db/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libsasl2-modules-db/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg-10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"4ff7bf0bc352412d","cpes":["cpe:2.3:a:sasl2-bin:sasl2-bin:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:sasl2-bin:sasl2_bin:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:sasl2_bin:sasl2-bin:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:sasl2_bin:sasl2_bin:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:sasl2:sasl2-bin:2.1.28\\+dfsg-10:*:*:*:*:*:*:*","cpe:2.3:a:sasl2:sasl2_bin:2.1.28\\+dfsg-10:*:*:*:*:*:*:*"],"name":"sasl2-bin","purl":"pkg:deb/debian/sasl2-bin@2.1.28%2Bdfsg-10?arch=amd64&distro=debian-12.15&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg-10","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause","BSD-4-clause-KTH","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","OpenSSL","RSA-MD","SSLeay"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sasl2-bin/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/sasl2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sasl2-bin.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sasl2-bin.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sasl2-bin.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.config"},{"path":"/var/lib/dpkg/info/sasl2-bin.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.list"},{"path":"/var/lib/dpkg/info/sasl2-bin.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.postinst"},{"path":"/var/lib/dpkg/info/sasl2-bin.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.postrm"},{"path":"/var/lib/dpkg/info/sasl2-bin.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.preinst"},{"path":"/var/lib/dpkg/info/sasl2-bin.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.prerm"},{"path":"/var/lib/dpkg/info/sasl2-bin.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sasl2-bin.templates"}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg-10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15919","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-15919","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15919","date":"2026-10-08","epss":0.03557,"percentile":0.89007}],"risk":0.17784999999999998,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15919","description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'"},"relatedVulnerabilities":[{"id":"CVE-2018-15919","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15919","date":"2026-10-08","epss":0.03557,"percentile":0.89007}],"urls":["http://seclists.org/oss-sec/2018/q3/180","http://www.securityfocus.com/bid/105163","https://security.netapp.com/advisory/ntap-20181221-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15919","description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'"}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"f3e6debe9866c7e0","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gh4c-6fx4-qh6g","versionConstraint":">=2.6.2,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-gh4c-6fx4-qh6g","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"risk":0.173145,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g","https://nvd.nist.gov/vuln/detail/CVE-2026-97688","https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gh4c-6fx4-qh6g","description":"urllib3: Chunked Deflate streaming can enter an infinite loop"},"relatedVulnerabilities":[{"id":"CVE-2026-97688","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"urls":["https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97688","description":"urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"6eae50b8c6e3da28","cpes":["cpe:2.3:a:libmariadb3:libmariadb3:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3","purl":"pkg:deb/debian/libmariadb3@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"risk":0.16873000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60184","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"a366b52f20cc78cd","cpes":["cpe:2.3:a:libmariadb3-compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3-compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3-compat","purl":"pkg:deb/debian/libmariadb3-compat@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3-compat/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3-compat/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"risk":0.16873000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60184","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"701b2e8ceba5d6be","cpes":["cpe:2.3:a:mariadb-client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client","purl":"pkg:deb/debian/mariadb-client@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.list"},{"path":"/var/lib/dpkg/info/mariadb-client.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postinst"},{"path":"/var/lib/dpkg/info/mariadb-client.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"risk":0.16873000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60184","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"b3cea487453c889f","cpes":["cpe:2.3:a:mariadb-client-core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client-core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client-core","purl":"pkg:deb/debian/mariadb-client-core@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client-core/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client-core/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"risk":0.16873000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60184","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"32abad22b22e448d","cpes":["cpe:2.3:a:mariadb-common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-common","purl":"pkg:deb/debian/mariadb-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.list"},{"path":"/var/lib/dpkg/info/mariadb-common.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postinst"},{"path":"/var/lib/dpkg/info/mariadb-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"risk":0.16873000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60184","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"de3ea55f6de1cad3","cpes":["cpe:2.3:a:mysql-common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql-common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mysql-common","purl":"pkg:deb/debian/mysql-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mysql-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mysql-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.list"},{"path":"/var/lib/dpkg/info/mysql-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60184","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"risk":0.16873000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60184","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60184","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60184","date":"2026-10-08","epss":0.00359,"percentile":0.27548}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60184","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-82049","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0a1, < 3.14.0b1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-82049","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0a1, < 3.14.0b1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.14.0b1"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-02","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-01","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-01","kind":"first-observed","version":"3.13.16"},{"date":"2026-09-22","kind":"first-observed","version":"3.14.0b1"},{"date":"2026-09-18","kind":"first-observed","version":"3.14.0b1"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.166155,"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."},"relatedVulnerabilities":[]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0-1+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25210","versionConstraint":"< 2.5.0-1+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-25210","fix":{"state":"fixed","versions":["2.5.0-1+deb12u4"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.5.0-1+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-25210","date":"2026-10-08","epss":0.00214,"percentile":0.10788}],"risk":0.16371,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-25210","description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation."},"relatedVulnerabilities":[{"id":"CVE-2026-25210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25210","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-25210","date":"2026-10-08","epss":0.00214,"percentile":0.10788}],"urls":["https://github.com/libexpat/libexpat/pull/1075","https://github.com/libexpat/libexpat/pull/1075/commits/9c2d990389e6abe2e44527eeaa8b39f16fe859c7","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25210","description":"In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53788","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53788","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53788","cwe":"CWE-93","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53788","date":"2026-10-08","epss":0.00272,"percentile":0.17938}],"risk":0.16184,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53788","description":"rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters into names communicated over the pipe-based line-oriented protocol to cause the rsync daemon to process attacker-influenced data as legitimate protocol input, corrupting uid/gid mapping logic."},"relatedVulnerabilities":[{"id":"CVE-2026-53788","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53788","cwe":"CWE-93","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53788","date":"2026-10-08","epss":0.00272,"percentile":0.17938}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-p4c5-8c68-5fjq","https://www.vulncheck.com/advisories/rsync-newline-injection-via-name-converter-uid-gid-mapping"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53788","description":"rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters into names communicated over the pipe-based line-oriented protocol to cause the rsync daemon to process attacker-influenced data as legitimate protocol input, corrupting uid/gid mapping logic."}]},{"artifact":{"id":"953752cd760533bf","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.42-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=pcre2","type":"deb","version":"10.42-1+deb12u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.42-1+deb12u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"< 10.42-1+deb12u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pcre2","version":"10.42-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"fixed","versions":["10.42-1+deb12u2"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"10.42-1+deb12u2"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"7d4a8150ae2dc1cd","cpes":["cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.18.8:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.18.8:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.18.8","type":"java-archive","version":"2.18.8","language":"java","licenses":["The Apache Software License, Version 2.0"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar:com.fasterxml.jackson.core:jackson-databind","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":null},"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/jars/ray_dist.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vvgp-rfg2-7rr6","versionConstraint":">=2.0.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.18.8"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vvgp-rfg2-7rr6","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"risk":0.161195,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6","https://nvd.nist.gov/vuln/detail/CVE-2026-77310","https://github.com/FasterXML/jackson-databind/pull/6058","https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vvgp-rfg2-7rr6","description":"jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-77310","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77310","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"0910b52008144867","cpes":["cpe:2.3:a:andrew_svetlov_project:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov_project:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlovproject:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlovproject:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python-multidict:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python-multidict:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python_multidict:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python_multidict:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov_project:multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew-svetlov:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew-svetlov:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlovproject:multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:multidict:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:multidict:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python-multidict:multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python_multidict:multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew-svetlov:multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov:multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:multidict:multidict:6.7.1:*:*:*:*:*:*:*","cpe:2.3:a:python:multidict:6.7.1:*:*:*:*:*:*:*"],"name":"multidict","purl":"pkg:pypi/multidict@6.7.1","type":"python","version":"6.7.1","language":"python","licenses":["Apache License 2.0"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/_private/runtime_env/agent/thirdparty_files/multidict-6.7.1.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/_private/runtime_env/agent/thirdparty_files/multidict-6.7.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/_private/runtime_env/agent/thirdparty_files/multidict-6.7.1.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/_private/runtime_env/agent/thirdparty_files/multidict-6.7.1.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/ray/_private/runtime_env/agent/thirdparty_files/multidict-6.7.1.dist-info/top_level.txt","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/ray/_private/runtime_env/agent/thirdparty_files/multidict-6.7.1.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-54p9-h82j-f925","versionConstraint":">=6.7.0,<=6.9.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"multidict","version":"6.7.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-54p9-h82j-f925","fix":{"state":"fixed","versions":["6.9.1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"6.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104874","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104874","date":"2026-10-08","epss":0.00297,"percentile":0.20566}],"risk":0.152955,"urls":["https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925","https://nvd.nist.gov/vuln/detail/CVE-2026-104874","https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40","https://github.com/aio-libs/multidict/releases/tag/v6.9.1"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-54p9-h82j-f925","description":"Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104874","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104874","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104874","date":"2026-10-08","epss":0.00297,"percentile":0.20566}],"urls":["https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40","https://github.com/aio-libs/multidict/releases/tag/v6.9.1","https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104874","description":"Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1."}]},{"artifact":{"id":"6067ed6f5124f197","cpes":["cpe:2.3:a:andrew_svetlov_project:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov_project:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlovproject:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlovproject:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python-multidict:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python-multidict:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python_multidict:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python_multidict:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov_project:multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew-svetlov:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew-svetlov:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlovproject:multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:multidict:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:multidict:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python-multidict:multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python_multidict:multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew-svetlov:multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:andrew_svetlov:multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python-multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python_multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:multidict:multidict:6.8.0:*:*:*:*:*:*:*","cpe:2.3:a:python:multidict:6.8.0:*:*:*:*:*:*:*"],"name":"multidict","purl":"pkg:pypi/multidict@6.8.0","type":"python","version":"6.8.0","language":"python","licenses":["Apache License 2.0"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/multidict-6.8.0.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/multidict-6.8.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/multidict-6.8.0.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/multidict-6.8.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/multidict-6.8.0.dist-info/top_level.txt","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/multidict-6.8.0.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-54p9-h82j-f925","versionConstraint":">=6.7.0,<=6.9.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"multidict","version":"6.8.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-54p9-h82j-f925","fix":{"state":"fixed","versions":["6.9.1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"6.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104874","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104874","date":"2026-10-08","epss":0.00297,"percentile":0.20566}],"risk":0.152955,"urls":["https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925","https://nvd.nist.gov/vuln/detail/CVE-2026-104874","https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40","https://github.com/aio-libs/multidict/releases/tag/v6.9.1"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-54p9-h82j-f925","description":"Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction"},"relatedVulnerabilities":[{"id":"CVE-2026-104874","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104874","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104874","date":"2026-10-08","epss":0.00297,"percentile":0.20566}],"urls":["https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40","https://github.com/aio-libs/multidict/releases/tag/v6.9.1","https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104874","description":"Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"ec8eb39ce089dc08","cpes":["cpe:2.3:a:curl:curl:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1965","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"risk":0.1518,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API)."},"relatedVulnerabilities":[{"id":"CVE-2026-1965","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API)."}]},{"artifact":{"id":"f49af56f3a8f57c1","cpes":["cpe:2.3:a:libcurl3-gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3-gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3_gnutls:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3-gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3:libcurl3_gnutls:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl3-gnutls","purl":"pkg:deb/debian/libcurl3-gnutls@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3-gnutls/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl3-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl3-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1965","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"risk":0.1518,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API)."},"relatedVulnerabilities":[{"id":"CVE-2026-1965","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API)."}]},{"artifact":{"id":"a6e2427d3e834f56","cpes":["cpe:2.3:a:libcurl4:libcurl4:7.88.1-10\\+deb12u15:*:*:*:*:*:*:*"],"name":"libcurl4","purl":"pkg:deb/debian/libcurl4@7.88.1-10%2Bdeb12u15?arch=amd64&distro=debian-12.15&upstream=curl","type":"deb","version":"7.88.1-10+deb12u15","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libcurl4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libcurl4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"curl","version":"7.88.1-10+deb12u15"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1965","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"risk":0.1518,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API)."},"relatedVulnerabilities":[{"id":"CVE-2026-1965","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API)."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58470","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-58470","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58470","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58470","date":"2026-10-08","epss":0.00247,"percentile":0.14668}],"risk":0.14696499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58470","description":"GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client."},"relatedVulnerabilities":[{"id":"CVE-2026-58470","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58470","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58470","date":"2026-10-08","epss":0.00247,"percentile":0.14668}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf","https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58470","description":"GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86143","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"risk":0.14356,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."},"relatedVulnerabilities":[{"id":"CVE-2026-86143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"urls":["https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-70454","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-70454","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70454","cwe":"CWE-295","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70454","date":"2026-10-08","epss":0.0019,"percentile":0.07879}],"risk":0.14345,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-70454","description":"rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client."},"relatedVulnerabilities":[{"id":"CVE-2026-70454","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","metrics":{"baseScore":8,"impactScore":5.8,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-70454","cwe":"CWE-295","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-70454","date":"2026-10-08","epss":0.0019,"percentile":0.07879}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-3c3x-ww2w-5r5p","https://www.vulncheck.com/advisories/rsync-tls-certificate-validation-bypass-via-ssl-openssl-mode"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-70454","description":"rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86144","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86144","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"risk":0.14229000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."},"relatedVulnerabilities":[{"id":"CVE-2026-86144","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"urls":["https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."}]},{"artifact":{"id":"d5e0daed57b0ef5c","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-1+deb12u2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"1853000d374a22b0","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/debian/passwd@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-1+deb12u2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11824","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11824","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"risk":0.14,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."},"relatedVulnerabilities":[{"id":"CVE-2026-11824","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."}]},{"artifact":{"id":"d08ba720d5534ad4","cpes":["cpe:2.3:a:sqlite3:sqlite3:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"sqlite3","purl":"pkg:deb/debian/sqlite3@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sqlite3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/sqlite3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sqlite3.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sqlite3.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11824","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11824","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"risk":0.14,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."},"relatedVulnerabilities":[{"id":"CVE-2026-11824","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/perl-base.prerm"},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"13b3922222ec533b","cpes":["cpe:2.3:a:perl-modules-5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.36:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-modules-5.36","purl":"pkg:deb/debian/perl-modules-5.36@5.36.0-7%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl-modules-5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.36.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl-modules-5.36.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-15310","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.13.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-15310","versionConstraint":"< 3.10.22||>= 3.11.0, < 3.11.17||>= 3.12.0, < 3.12.15||>= 3.13.0, < 3.13.16||>= 3.14.0, < 3.14.8||>= 3.15.0a1, < 3.15.0rc2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16","3.14.8","3.15.0rc2"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"3.10.22"},{"date":"2026-10-02","kind":"first-observed","version":"3.11.17"},{"date":"2026-10-01","kind":"first-observed","version":"3.12.15"},{"date":"2026-10-01","kind":"first-observed","version":"3.13.16"},{"date":"2026-10-01","kind":"first-observed","version":"3.14.8"},{"date":"2026-09-22","kind":"first-observed","version":"3.15.0rc2"},{"date":"2026-09-09","kind":"first-observed","version":"3.15.0rc2"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.13413,"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106552","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106552","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-08","epss":0.00291,"percentile":0.19813}],"risk":0.13385999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106552","description":"In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation."},"relatedVulnerabilities":[{"id":"CVE-2026-106552","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-08","epss":0.00291,"percentile":0.19813}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106552","description":"In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"58f3a3d22240a914","cpes":["cpe:2.3:a:git:git:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"name":"git","purl":"pkg:deb/debian/git@1%3A2.39.5-0%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"1:2.39.5-0+deb12u3","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-24975","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"risk":0.1312,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."},"relatedVulnerabilities":[{"id":"CVE-2022-24975","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."}]},{"artifact":{"id":"d2fedb9664730c69","cpes":["cpe:2.3:a:git-man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.39.5-0\\+deb12u3:*:*:*:*:*:*:*"],"name":"git-man","purl":"pkg:deb/debian/git-man@1%3A2.39.5-0%2Bdeb12u3?arch=all&distro=debian-12.15&upstream=git","type":"deb","version":"1:2.39.5-0+deb12u3","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/git-man.list"}],"upstreams":[{"name":"git"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"git","version":"1:2.39.5-0+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-24975","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"risk":0.1312,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."},"relatedVulnerabilities":[{"id":"CVE-2022-24975","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"4cab7ef7de016d31","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"372dffabd059479c","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"ca1034d5d24bcf54","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"87d8465053cf56c8","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"eca37691b87c0860","cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","type":"deb","version":"9.1-1","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"1e5c5363a73cf859","cpes":["cpe:2.3:a:ldap-utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap-utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap_utils:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap-utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:ldap:ldap_utils:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"ldap-utils","purl":"pkg:deb/debian/ldap-utils@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ldap-utils/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/ldap-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ldap-utils.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/ldap-utils.list"}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2020-15719","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"risk":0.12575,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."},"relatedVulnerabilities":[{"id":"CVE-2020-15719","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."}]},{"artifact":{"id":"692b9197d4b21a92","cpes":["cpe:2.3:a:libldap-2.5-0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5-0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5_0:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap-2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap_2.5:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap-2.5-0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*","cpe:2.3:a:libldap:libldap_2.5_0:2.5.13\\+dfsg-5:*:*:*:*:*:*:*"],"name":"libldap-2.5-0","purl":"pkg:deb/debian/libldap-2.5-0@2.5.13%2Bdfsg-5?arch=amd64&distro=debian-12.15&upstream=openldap","type":"deb","version":"2.5.13+dfsg-5","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap-2.5-0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libldap-2.5-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libldap-2.5-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openldap","version":"2.5.13+dfsg-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2020-15719","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"risk":0.12575,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."},"relatedVulnerabilities":[{"id":"CVE-2020-15719","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."}]},{"artifact":{"id":"6eae50b8c6e3da28","cpes":["cpe:2.3:a:libmariadb3:libmariadb3:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3","purl":"pkg:deb/debian/libmariadb3@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-44169","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"risk":0.125085,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."},"relatedVulnerabilities":[{"id":"CVE-2026-44169","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"urls":["https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2","https://jira.mariadb.org/browse/MDEV-39288"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."}]},{"artifact":{"id":"a366b52f20cc78cd","cpes":["cpe:2.3:a:libmariadb3-compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3-compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3-compat","purl":"pkg:deb/debian/libmariadb3-compat@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3-compat/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3-compat/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-44169","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"risk":0.125085,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."},"relatedVulnerabilities":[{"id":"CVE-2026-44169","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"urls":["https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2","https://jira.mariadb.org/browse/MDEV-39288"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."}]},{"artifact":{"id":"701b2e8ceba5d6be","cpes":["cpe:2.3:a:mariadb-client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client","purl":"pkg:deb/debian/mariadb-client@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.list"},{"path":"/var/lib/dpkg/info/mariadb-client.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postinst"},{"path":"/var/lib/dpkg/info/mariadb-client.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-44169","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"risk":0.125085,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."},"relatedVulnerabilities":[{"id":"CVE-2026-44169","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"urls":["https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2","https://jira.mariadb.org/browse/MDEV-39288"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."}]},{"artifact":{"id":"b3cea487453c889f","cpes":["cpe:2.3:a:mariadb-client-core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client-core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client-core","purl":"pkg:deb/debian/mariadb-client-core@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client-core/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client-core/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-44169","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"risk":0.125085,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."},"relatedVulnerabilities":[{"id":"CVE-2026-44169","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"urls":["https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2","https://jira.mariadb.org/browse/MDEV-39288"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."}]},{"artifact":{"id":"32abad22b22e448d","cpes":["cpe:2.3:a:mariadb-common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-common","purl":"pkg:deb/debian/mariadb-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.list"},{"path":"/var/lib/dpkg/info/mariadb-common.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postinst"},{"path":"/var/lib/dpkg/info/mariadb-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-44169","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"risk":0.125085,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."},"relatedVulnerabilities":[{"id":"CVE-2026-44169","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"urls":["https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2","https://jira.mariadb.org/browse/MDEV-39288"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."}]},{"artifact":{"id":"de3ea55f6de1cad3","cpes":["cpe:2.3:a:mysql-common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql-common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mysql-common","purl":"pkg:deb/debian/mysql-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mysql-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mysql-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.list"},{"path":"/var/lib/dpkg/info/mysql-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44169","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-44169","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"risk":0.125085,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."},"relatedVulnerabilities":[{"id":"CVE-2026-44169","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44169","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44169","date":"2026-10-08","epss":0.00269,"percentile":0.17479}],"urls":["https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2","https://jira.mariadb.org/browse/MDEV-39288"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44169","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-2243","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-2243","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2243","date":"2026-10-08","epss":0.02472,"percentile":0.84043}],"risk":0.12360000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2243","description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483."},"relatedVulnerabilities":[{"id":"CVE-2007-2243","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2243","date":"2026-10-08","epss":0.02472,"percentile":0.84043}],"urls":["http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053906.html","http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053951.html","http://securityreason.com/securityalert/2631","http://www.osvdb.org/34600","http://www.securityfocus.com/bid/23601","https://exchange.xforce.ibmcloud.com/vulnerabilities/33794","https://security.netapp.com/advisory/ntap-20191107-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2243","description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"2d7a9944fa0f8f96","cpes":["cpe:2.3:a:python-virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:virtualenv:21.7.9:*:*:*:*:*:*:*"],"name":"virtualenv","purl":"pkg:pypi/virtualenv@21.7.9","type":"python","version":"21.7.9","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.7.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-94p9-xgh2-xp45","versionConstraint":"<=21.7.11 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"virtualenv","version":"21.7.9"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-94p9-xgh2-xp45","fix":{"state":"fixed","versions":["21.7.12"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"21.7.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102930","cwe":"CWE-494","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102930","date":"2026-10-08","epss":0.0016,"percentile":0.04545}],"risk":0.12160000000000001,"urls":["https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45","https://nvd.nist.gov/vuln/detail/CVE-2026-102930","https://github.com/pypa/virtualenv/pull/3251","https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d","https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4011.yaml","https://github.com/pypa/virtualenv","https://github.com/pypa/virtualenv/releases/tag/21.7.12","https://pypi.org/project/virtualenv"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-94p9-xgh2-xp45","description":"virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use"},"relatedVulnerabilities":[{"id":"CVE-2026-102930","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102930","cwe":"CWE-494","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102930","date":"2026-10-08","epss":0.0016,"percentile":0.04545}],"urls":["https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d","https://github.com/pypa/virtualenv/pull/3251","https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102930","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86140","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86140","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.12010499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86140","description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-86140","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86140","description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86142","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86142","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"risk":0.12010499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."},"relatedVulnerabilities":[{"id":"CVE-2026-86142","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"urls":["https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"127f2ae91adc51ae","cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libxslt1.1","purl":"pkg:deb/debian/libxslt1.1@1.1.35-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=libxslt","type":"deb","version":"1.1.35-1+deb12u4","language":"","licenses":["sha256:4b82c8dd6e55001a5921bea1d6db20be5c51e5976d892e870324026c23f37b6f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxslt1.1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxslt1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxslt"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-9019","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxslt","version":"1.1.35-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2015-9019","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2015-9019","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-9019","date":"2026-10-08","epss":0.02393,"percentile":0.83472}],"risk":0.11965,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-9019","description":"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs."},"relatedVulnerabilities":[{"id":"CVE-2015-9019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2015-9019","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2015-9019","date":"2026-10-08","epss":0.02393,"percentile":0.83472}],"urls":["https://bugzilla.gnome.org/show_bug.cgi?id=758400","https://bugzilla.suse.com/show_bug.cgi?id=934119"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-9019","description":"In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"2d7a9944fa0f8f96","cpes":["cpe:2.3:a:python-virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:virtualenv:21.7.9:*:*:*:*:*:*:*"],"name":"virtualenv","purl":"pkg:pypi/virtualenv@21.7.9","type":"python","version":"21.7.9","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.7.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p58f-9548-mpm2","versionConstraint":"<=21.7.12 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"virtualenv","version":"21.7.9"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-p58f-9548-mpm2","fix":{"state":"fixed","versions":["21.7.13"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"21.7.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102925","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102925","date":"2026-10-08","epss":0.00153,"percentile":0.03865}],"risk":0.117045,"urls":["https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2","https://nvd.nist.gov/vuln/detail/CVE-2026-102925","https://github.com/pypa/virtualenv/pull/3252","https://github.com/pypa/virtualenv/commit/4d5a105ec2a2723b8c7f4571bb68f4f71d01e3f6","https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4013.yaml","https://github.com/pypa/virtualenv","https://github.com/pypa/virtualenv/releases/tag/21.7.13","https://pypi.org/project/virtualenv"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p58f-9548-mpm2","description":"virtualenv bash and fish activation scripts execute commands embedded in paths"},"relatedVulnerabilities":[{"id":"CVE-2026-102925","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102925","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102925","date":"2026-10-08","epss":0.00153,"percentile":0.03865}],"urls":["https://github.com/pypa/virtualenv/commit/4d5a105ec2a2723b8c7f4571bb68f4f71d01e3f6","https://github.com/pypa/virtualenv/pull/3252","https://github.com/pypa/virtualenv/releases/tag/21.7.13","https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102925","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user's privileges. This issue is fixed in version 21.7.13."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53785","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53785","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53785","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53785","date":"2026-10-08","epss":0.00192,"percentile":0.08136}],"risk":0.11424000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53785","description":"rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating intermediate directories without verifying that created paths remain within the destination boundary, enabling arbitrary file writes on the receiver's filesystem."},"relatedVulnerabilities":[{"id":"CVE-2026-53785","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53785","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53785","date":"2026-10-08","epss":0.00192,"percentile":0.08136}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-pph3-7xmf-rrqg","https://www.vulncheck.com/advisories/rsync-path-traversal-write-escape-via-relative-mode"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53785","description":"rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating intermediate directories without verifying that created paths remain within the destination boundary, enabling arbitrary file writes on the receiver's filesystem."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"0027543880aaec84","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.24.1-2?arch=amd64&distro=debian-12.15&upstream=p11-kit","type":"deb","version":"0.24.1-2","language":"","licenses":["Apache-2.0","BSD-3-Clause","ISC","ISC+IBM","LGPL-2.1","LGPL-2.1+","permissive-like-automake-output","same-as-rest-of-p11kit"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"p11-kit","version":"0.24.1-2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13757","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"risk":0.11312000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."},"relatedVulnerabilities":[{"id":"CVE-2026-13757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."}]},{"artifact":{"id":"d047530090108251","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.1-3:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/debian/libacl1@2.3.1-3?arch=amd64&distro=debian-12.15&upstream=acl","type":"deb","version":"2.3.1-3","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"acl","version":"2.3.1-3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.11168999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-106585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-08","epss":0.00189,"percentile":0.07871}],"risk":0.10867499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106585","description":"In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data."},"relatedVulnerabilities":[{"id":"CVE-2026-106585","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-08","epss":0.00189,"percentile":0.07871}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106585","description":"In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.106575,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"2d7a9944fa0f8f96","cpes":["cpe:2.3:a:python-virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:python-virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:python_virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:virtualenv:21.7.9:*:*:*:*:*:*:*","cpe:2.3:a:python:virtualenv:21.7.9:*:*:*:*:*:*:*"],"name":"virtualenv","purl":"pkg:pypi/virtualenv@21.7.9","type":"python","version":"21.7.9","language":"python","licenses":["MIT"],"locations":[{"path":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/METADATA","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/RECORD","layerID":"sha256:1921e48cfe7e40daaf8392904e3f2a2fcf2b9092fe450c4d40ddc003e5e4394e","accessPath":"/home/airflow/.local/lib/python3.13/site-packages/virtualenv-21.7.9.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.7.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x78j-v8h9-3j2q","versionConstraint":"<=21.7.11 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"virtualenv","version":"21.7.9"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-x78j-v8h9-3j2q","fix":{"state":"fixed","versions":["21.7.12"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"21.7.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102937","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102937","date":"2026-10-08","epss":0.0014,"percentile":0.02884}],"risk":0.1036,"urls":["https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q","https://nvd.nist.gov/vuln/detail/CVE-2026-102937","https://github.com/pypa/virtualenv/pull/3250","https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6","https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4014.yaml","https://github.com/pypa/virtualenv","https://github.com/pypa/virtualenv/releases/tag/21.7.12","https://pypi.org/project/virtualenv"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x78j-v8h9-3j2q","description":"virtualenv: Command injection via --prompt in activate.bat (batch activator)"},"relatedVulnerabilities":[{"id":"CVE-2026-102937","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102937","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102937","date":"2026-10-08","epss":0.0014,"percentile":0.02884}],"urls":["https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6","https://github.com/pypa/virtualenv/pull/3250","https://github.com/pypa/virtualenv/releases/tag/21.7.12","https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102937","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set \"VAR=value\" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2020-14145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14145","date":"2026-10-08","epss":0.02057,"percentile":0.80701}],"risk":0.10285000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-14145","description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected."},"relatedVulnerabilities":[{"id":"CVE-2020-14145","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14145","date":"2026-10-08","epss":0.02057,"percentile":0.80701}],"urls":["http://www.openwall.com/lists/oss-security/2020/12/02/1","https://anongit.mindrot.org/openssh.git/commit/?id=b3855ff053f5078ec3d3c653cdaedefaa5fc362d","https://docs.ssh-mitm.at/CVE-2020-14145.html","https://github.com/openssh/openssh-portable/compare/V_8_3_P1...V_8_4_P1","https://github.com/ssh-mitm/ssh-mitm/blob/master/ssh_proxy_server/plugins/session/cve202014145.py","https://security.gentoo.org/glsa/202105-35","https://security.netapp.com/advisory/ntap-20200709-0004/","https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14145","description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected."}]},{"artifact":{"id":"a839353ae380ee36","cpes":["cpe:2.3:a:krb5-user:krb5-user:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5-user:krb5_user:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_user:krb5-user:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5_user:krb5_user:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-user:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_user:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"krb5-user","purl":"pkg:deb/debian/krb5-user@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/krb5-user/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/krb5-user/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-user.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/krb5-user.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/krb5-user.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/krb5-user.list"}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"9db16cb04ae3b83d","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"84bafd466aa0b9cb","cpes":["cpe:2.3:a:libgssrpc4:libgssrpc4:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libgssrpc4","purl":"pkg:deb/debian/libgssrpc4@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssrpc4/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libgssrpc4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssrpc4:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libgssrpc4:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"fb1c9cf5b43a5af0","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"40d9122606c7e8c9","cpes":["cpe:2.3:a:libkadm5clnt-mit12:libkadm5clnt-mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5clnt-mit12:libkadm5clnt_mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5clnt_mit12:libkadm5clnt-mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5clnt_mit12:libkadm5clnt_mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5clnt:libkadm5clnt-mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5clnt:libkadm5clnt_mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkadm5clnt-mit12","purl":"pkg:deb/debian/libkadm5clnt-mit12@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkadm5clnt-mit12/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libkadm5clnt-mit12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkadm5clnt-mit12:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libkadm5clnt-mit12:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"f76b00847802d474","cpes":["cpe:2.3:a:libkadm5srv-mit12:libkadm5srv-mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5srv-mit12:libkadm5srv_mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5srv_mit12:libkadm5srv-mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5srv_mit12:libkadm5srv_mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5srv:libkadm5srv-mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkadm5srv:libkadm5srv_mit12:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkadm5srv-mit12","purl":"pkg:deb/debian/libkadm5srv-mit12@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkadm5srv-mit12/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libkadm5srv-mit12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkadm5srv-mit12:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libkadm5srv-mit12:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"6d72522be9bb65a8","cpes":["cpe:2.3:a:libkdb5-10:libkdb5-10:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkdb5-10:libkdb5_10:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkdb5_10:libkdb5-10:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkdb5_10:libkdb5_10:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkdb5:libkdb5-10:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkdb5:libkdb5_10:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkdb5-10","purl":"pkg:deb/debian/libkdb5-10@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkdb5-10/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libkdb5-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkdb5-10:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libkdb5-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"52548f50c4ff26c7","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"309b5ab55a11c7d0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"3c692bddfcfc9789","cpes":["cpe:2.3:a:sudo:sudo:1.9.13p3-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"sudo","purl":"pkg:deb/debian/sudo@1.9.13p3-1%2Bdeb12u4?arch=amd64&distro=debian-12.15","type":"deb","version":"1.9.13p3-1+deb12u4","language":"","licenses":["BSD-2-Clause","BSD-3-Clause","ISC","Zlib","other","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sudo/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/sudo/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sudo.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sudo.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sudo.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.list"},{"path":"/var/lib/dpkg/info/sudo.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.postinst"},{"path":"/var/lib/dpkg/info/sudo.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.postrm"},{"path":"/var/lib/dpkg/info/sudo.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.preinst"},{"path":"/var/lib/dpkg/info/sudo.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.prerm"},{"path":"/var/lib/dpkg/info/sudo.shlibs","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.shlibs"},{"path":"/var/lib/dpkg/info/sudo.triggers","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/sudo.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-96512","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sudo","version":"1.9.13p3-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-96512","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96512","cwe":"CWE-863","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-96512","date":"2026-10-08","epss":0.00133,"percentile":0.02412}],"risk":0.101745,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-96512","description":"A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected."},"relatedVulnerabilities":[{"id":"CVE-2026-96512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96512","cwe":"CWE-863","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-96512","date":"2026-10-08","epss":0.00133,"percentile":0.02412}],"urls":["https://access.redhat.com/errata/RHSA-2026:71609","https://access.redhat.com/errata/RHSA-2026:75571","https://access.redhat.com/errata/RHSA-2026:75579","https://access.redhat.com/errata/RHSA-2026:75580","https://access.redhat.com/security/cve/CVE-2026-96512","https://bugzilla.redhat.com/show_bug.cgi?id=2539327","https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c","http://www.openwall.com/lists/oss-security/2026/09/24/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-96512","description":"A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected."}]},{"artifact":{"id":"722285f8005c2384","cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.1-4:*:*:*:*:*:*:*"],"name":"libattr1","purl":"pkg:deb/debian/libattr1@1%3A2.5.1-4?arch=amd64&distro=debian-12.15&upstream=attr","type":"deb","version":"1:2.5.1-4","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libattr1/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libattr1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"attr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"attr","version":"1:2.5.1-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54371","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"risk":0.10113499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."},"relatedVulnerabilities":[{"id":"CVE-2026-54371","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/errata/RHSA-2026:56133","https://access.redhat.com/errata/RHSA-2026:59380","https://access.redhat.com/errata/RHSA-2026:60226","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86138","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86138","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"risk":0.10097999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-86138","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"urls":["https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."}]},{"artifact":{"id":"077923f667034501","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","type":"deb","version":"1:1.2.13.dfsg-1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.10027499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"6ac7355626cdfddd","cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:generic/python@3.13.15","type":"binary","version":"3.13.15","language":"","licenses":[],"locations":[{"path":"/usr/python/bin/python3.13","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/bin/python3.13","annotations":{"evidence":"primary"}},{"path":"/usr/python/lib/libpython3.13.so.1.0","layerID":"sha256:e7dd880ea5e31fb9316572089f74fca69cce18189b6f0c209ac213c8e686f21f","accessPath":"/usr/python/lib/libpython3.13.so.1.0","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.15.0rc3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12345","versionConstraint":"< 3.15.0rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"3.15.0rc3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12345","versionConstraint":"< 3.15.0rc3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.13.15:*:*:*:*:*:*:*"],"package":{"name":"python","version":"3.13.15"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"fixed","versions":["3.15.0rc3"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"3.15.0rc3"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"fa80a0ecce33665f","cpes":["cpe:2.3:a:libc-l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_l10n:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_l10n:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-l10n","purl":"pkg:deb/debian/libc-l10n@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libc-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libc-l10n.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"980f6ab12ca359c9","cpes":["cpe:2.3:a:locales:locales:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/debian/locales@2.36-9%2Bdeb12u14?arch=all&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"6eae50b8c6e3da28","cpes":["cpe:2.3:a:libmariadb3:libmariadb3:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3","purl":"pkg:deb/debian/libmariadb3@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60747","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60747","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"risk":0.09688000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60747","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"a366b52f20cc78cd","cpes":["cpe:2.3:a:libmariadb3-compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3-compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3-compat","purl":"pkg:deb/debian/libmariadb3-compat@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3-compat/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3-compat/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60747","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60747","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"risk":0.09688000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60747","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"701b2e8ceba5d6be","cpes":["cpe:2.3:a:mariadb-client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client","purl":"pkg:deb/debian/mariadb-client@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.list"},{"path":"/var/lib/dpkg/info/mariadb-client.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postinst"},{"path":"/var/lib/dpkg/info/mariadb-client.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60747","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60747","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"risk":0.09688000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60747","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"b3cea487453c889f","cpes":["cpe:2.3:a:mariadb-client-core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client-core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client-core","purl":"pkg:deb/debian/mariadb-client-core@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client-core/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client-core/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60747","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60747","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"risk":0.09688000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60747","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"32abad22b22e448d","cpes":["cpe:2.3:a:mariadb-common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-common","purl":"pkg:deb/debian/mariadb-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.list"},{"path":"/var/lib/dpkg/info/mariadb-common.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postinst"},{"path":"/var/lib/dpkg/info/mariadb-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60747","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60747","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"risk":0.09688000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60747","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"de3ea55f6de1cad3","cpes":["cpe:2.3:a:mysql-common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql-common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mysql-common","purl":"pkg:deb/debian/mysql-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mysql-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mysql-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.list"},{"path":"/var/lib/dpkg/info/mysql-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60747","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-60747","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"risk":0.09688000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."},"relatedVulnerabilities":[{"id":"CVE-2026-60747","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60747","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-60747","date":"2026-10-08","epss":0.00173,"percentile":0.06121}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60747","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."}]},{"artifact":{"id":"45ca0a14113d5717","cpes":["cpe:2.3:a:libncurses6:libncurses6:6.4-4:*:*:*:*:*:*:*"],"name":"libncurses6","purl":"pkg:deb/debian/libncurses6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libncurses6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"c185e9c791136aa6","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/debian/dirmngr@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"e92d6b046326efbc","cpes":["cpe:2.3:a:gnupg:gnupg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/debian/gnupg@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"976c5c43a7fe516a","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/debian/gnupg-l10n@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"4d2b57169c4709a4","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/debian/gnupg-utils@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"06d667f09914c357","cpes":["cpe:2.3:a:gnupg2:gnupg2:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gnupg2","purl":"pkg:deb/debian/gnupg2@2.2.40-1.1%2Bdeb12u2?arch=all&distro=debian-12.15","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gnupg2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg2.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg2.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gnupg2.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"1b50350895a48a3b","cpes":["cpe:2.3:a:gpg:gpg:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/debian/gpg@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"01ceda49a85ecdc9","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/debian/gpg-agent@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"2ce7ba29a10f5f2d","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/debian/gpg-wks-client@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"5c929b5e7563826e","cpes":["cpe:2.3:a:gpg-wks-server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_server:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_server:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpg-wks-server","purl":"pkg:deb/debian/gpg-wks-server@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-server/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gpg-wks-server/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-wks-server.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-server.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpg-wks-server.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"45da524630bb2133","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/debian/gpgconf@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"b982b129e67b17ad","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/debian/gpgsm@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"bab4532a87a829c8","cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"6eae50b8c6e3da28","cpes":["cpe:2.3:a:libmariadb3:libmariadb3:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3","purl":"pkg:deb/debian/libmariadb3@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61081","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-61081","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"risk":0.092055,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."},"relatedVulnerabilities":[{"id":"CVE-2026-61081","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"a366b52f20cc78cd","cpes":["cpe:2.3:a:libmariadb3-compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3-compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3_compat:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3-compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:libmariadb3:libmariadb3_compat:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"libmariadb3-compat","purl":"pkg:deb/debian/libmariadb3-compat@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmariadb3-compat/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/libmariadb3-compat/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmariadb3-compat.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/libmariadb3-compat.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61081","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-61081","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"risk":0.092055,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."},"relatedVulnerabilities":[{"id":"CVE-2026-61081","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"701b2e8ceba5d6be","cpes":["cpe:2.3:a:mariadb-client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client","purl":"pkg:deb/debian/mariadb-client@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.list"},{"path":"/var/lib/dpkg/info/mariadb-client.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postinst"},{"path":"/var/lib/dpkg/info/mariadb-client.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61081","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-61081","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"risk":0.092055,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."},"relatedVulnerabilities":[{"id":"CVE-2026-61081","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"b3cea487453c889f","cpes":["cpe:2.3:a:mariadb-client-core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client-core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client_core:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_client:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-client-core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_client_core:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-client-core","purl":"pkg:deb/debian/mariadb-client-core@1%3A10.11.19%2Bmaria~deb12?arch=amd64&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-client-core/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-client-core/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-client-core.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-client-core.list"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61081","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-61081","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"risk":0.092055,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."},"relatedVulnerabilities":[{"id":"CVE-2026-61081","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"32abad22b22e448d","cpes":["cpe:2.3:a:mariadb-common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb-common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb_common:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mariadb-common","purl":"pkg:deb/debian/mariadb-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mariadb-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mariadb-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.conffiles","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mariadb-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.list"},{"path":"/var/lib/dpkg/info/mariadb-common.postinst","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postinst"},{"path":"/var/lib/dpkg/info/mariadb-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mariadb-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61081","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-61081","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"risk":0.092055,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."},"relatedVulnerabilities":[{"id":"CVE-2026-61081","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"de3ea55f6de1cad3","cpes":["cpe:2.3:a:mysql-common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql-common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql_common:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql-common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*","cpe:2.3:a:mysql:mysql_common:1\\:10.11.19\\+maria\\~deb12:*:*:*:*:*:*:*"],"name":"mysql-common","purl":"pkg:deb/debian/mysql-common@1%3A10.11.19%2Bmaria~deb12?arch=all&distro=debian-12.15&upstream=mariadb","type":"deb","version":"1:10.11.19+maria~deb12","language":"","licenses":["sha256:2c6eb2ec4b682e43969f1db4da02bbaed33cc51f16b7170f990ae6d50271bf5b"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mysql-common/copyright","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/usr/share/doc/mysql-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.md5sums","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mysql-common.list","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.list"},{"path":"/var/lib/dpkg/info/mysql-common.postrm","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/info/mysql-common.postrm"}],"upstreams":[{"name":"mariadb"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61081","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"mariadb","version":"1:10.11.19+maria~deb12"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-61081","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"risk":0.092055,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."},"relatedVulnerabilities":[{"id":"CVE-2026-61081","cvss":[{"type":"Secondary","source":"secalert_us@oracle.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61081","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-61081","date":"2026-10-08","epss":0.00323,"percentile":0.23272}],"urls":["https://www.oracle.com/security-alerts/cpujul2026.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61081","description":"Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)."}]},{"artifact":{"id":"0657da36f7d81648","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u3:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u3","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0-1+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32777","versionConstraint":"< 2.5.0-1+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-32777","fix":{"state":"fixed","versions":["2.5.0-1+deb12u4"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.5.0-1+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32777","date":"2026-10-08","epss":0.00174,"percentile":0.06263}],"risk":0.09135,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-32777","description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content."},"relatedVulnerabilities":[{"id":"CVE-2026-32777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32777","date":"2026-10-08","epss":0.00174,"percentile":0.06263}],"urls":["https://github.com/libexpat/libexpat/issues/1161","https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1162","https://issues.oss-fuzz.com/issues/486993411","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32777","description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content."}]},{"artifact":{"id":"d82af4e74abd89bc","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:9.2p1-2\\+deb12u10:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A9.2p1-2%2Bdeb12u10?arch=amd64&distro=debian-12.15&upstream=openssh","type":"deb","version":"1:9.2p1-2+deb12u10","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssh","version":"1:9.2p1-2+deb12u10"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"127f2ae91adc51ae","cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.35-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libxslt1.1","purl":"pkg:deb/debian/libxslt1.1@1.1.35-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=libxslt","type":"deb","version":"1.1.35-1+deb12u4","language":"","licenses":["sha256:4b82c8dd6e55001a5921bea1d6db20be5c51e5976d892e870324026c23f37b6f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxslt1.1/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxslt1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxslt"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-10911","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxslt","version":"1.1.35-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-10911","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10911","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-10911","date":"2026-10-08","epss":0.00173,"percentile":0.06072}],"risk":0.090825,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10911","description":"A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash."},"relatedVulnerabilities":[{"id":"CVE-2025-10911","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10911","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-10911","date":"2026-10-08","epss":0.00173,"percentile":0.06072}],"urls":["https://access.redhat.com/errata/RHSA-2026:11015","https://access.redhat.com/errata/RHSA-2026:26355","https://access.redhat.com/errata/RHSA-2026:28243","https://access.redhat.com/errata/RHSA-2026:28584","https://access.redhat.com/errata/RHSA-2026:29807","https://access.redhat.com/errata/RHSA-2026:29809","https://access.redhat.com/errata/RHSA-2026:29811","https://access.redhat.com/errata/RHSA-2026:29814","https://access.redhat.com/errata/RHSA-2026:29975","https://access.redhat.com/errata/RHSA-2026:29976","https://access.redhat.com/errata/RHSA-2026:30847","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2025-10911","https://bugzilla.redhat.com/show_bug.cgi?id=2397838","https://gitlab.gnome.org/GNOME/libxslt/-/issues/144","https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/77"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10911","description":"A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash."}]},{"artifact":{"id":"3033b91dd67880ed","cpes":["cpe:2.3:a:rsync:rsync:3.2.7-1\\+deb12u6:*:*:*:*:*:*:*"],"name":"rsync","purl":"pkg:deb/debian/rsync@3.2.7-1%2Bdeb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"3.2.7-1+deb12u6","language":"","licenses":["sha256:240afc05aff098e53dafe0def34030b2ef7848b78b9ebabf2c157713b9f975c5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/rsync/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/rsync/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/rsync.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.list"},{"path":"/var/lib/dpkg/info/rsync.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postinst"},{"path":"/var/lib/dpkg/info/rsync.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.postrm"},{"path":"/var/lib/dpkg/info/rsync.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.preinst"},{"path":"/var/lib/dpkg/info/rsync.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/rsync.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53799","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"rsync","version":"3.2.7-1+deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53799","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53799","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53799","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53799","date":"2026-10-08","epss":0.00122,"percentile":0.01803}],"risk":0.08967,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53799","description":"rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-53799","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53799","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-53799","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-53799","date":"2026-10-08","epss":0.00122,"percentile":0.01803}],"urls":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-phxh-hjqv-39c9","https://www.vulncheck.com/advisories/rsync-symlink-race-condition-via-acl-xattr-application"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53799","description":"rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation."}]},{"artifact":{"id":"ef5a5a7d880f3e73","cpes":["cpe:2.3:a:wget:wget:1.21.3-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/debian/wget@1.21.3-1%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.21.3-1+deb12u1","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15146","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"wget","version":"1.21.3-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15146","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"impactScore":3.4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15146","date":"2026-10-08","epss":0.00164,"percentile":0.05137}],"risk":0.08938,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15146","description":"GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources."},"relatedVulnerabilities":[{"id":"CVE-2026-15146","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"impactScore":3.4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-15146","date":"2026-10-08","epss":0.00164,"percentile":0.05137}],"urls":["https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b","https://kb.cert.org/vuls/id/564823","https://www.kb.cert.org/vuls/id/564823"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15146","description":"GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources."}]},{"artifact":{"id":"751ec9ae4280dd32","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/debian/libbz2-1.0@1.0.8-5%2Bb1?arch=amd64&distro=debian-12.15&upstream=bzip2%401.0.8-5","type":"deb","version":"1.0.8-5+b1","language":"","licenses":["BSD-variant","GPL-2"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2","version":"1.0.8-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bzip2","version":"1.0.8-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.08918,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"df01c68aff59530a","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/debian/libgcrypt20@1.10.1-3%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.10.1-3+deb12u1","language":"","licenses":["sha256:95db2f9da663f2bfe2aabe9c72fce9d6c9ae767b912f397d7823f50bd55a1a7d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:1d69a5fd31932841d7825ef4780c06f008eea65aaa9f3110fe09d5832ed5c7d8","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libgcrypt20","version":"1.10.1-3+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-6829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-08","epss":0.01777,"percentile":0.77546}],"risk":0.08885000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."},"relatedVulnerabilities":[{"id":"CVE-2018-6829","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-08","epss":0.01777,"percentile":0.77546}],"urls":["https://github.com/weikengchen/attack-on-libgcrypt-elgamal","https://github.com/weikengchen/attack-on-libgcrypt-elgamal/wiki","https://lists.gnupg.org/pipermail/gcrypt-devel/2018-February/004394.html","https://www.oracle.com/security-alerts/cpujan2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."}]},{"artifact":{"id":"f55823b1f5c2e201","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"7345802bd2ec0962","cpes":["cpe:2.3:a:openssl:openssl:3.0.20-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.0.20-1~deb12u2?arch=amd64&distro=debian-12.15","type":"deb","version":"3.0.20-1~deb12u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.20-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"dee83f732098ecac","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3\\~deb12u6:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.9.14%2Bdfsg-1.3~deb12u6?arch=amd64&distro=debian-12.15","type":"deb","version":"2.9.14+dfsg-1.3~deb12u6","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3~deb12u6"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"risk":0.087675,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76781","description":"A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-76781","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"urls":["https://access.redhat.com/errata/RHSA-2026:57604","https://access.redhat.com/security/cve/CVE-2026-76781","https://bugzilla.redhat.com/show_bug.cgi?id=2519776","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c6324894","https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/442"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76781","description":"A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS)."}]},{"artifact":{"id":"48182e8b6f91fbcf","cpes":["cpe:2.3:a:iputils-ping:iputils-ping:3\\:20221126-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:iputils-ping:iputils_ping:3\\:20221126-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:iputils_ping:iputils-ping:3\\:20221126-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:iputils_ping:iputils_ping:3\\:20221126-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:iputils:iputils-ping:3\\:20221126-1\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:iputils:iputils_ping:3\\:20221126-1\\+deb12u1:*:*:*:*:*:*:*"],"name":"iputils-ping","purl":"pkg:deb/debian/iputils-ping@3%3A20221126-1%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=iputils","type":"deb","version":"3:20221126-1+deb12u1","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/iputils-ping/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/iputils-ping/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/iputils-ping.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/iputils-ping.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/iputils-ping.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/iputils-ping.list"},{"path":"/var/lib/dpkg/info/iputils-ping.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/iputils-ping.postinst"}],"upstreams":[{"name":"iputils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-47268","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"iputils","version":"3:20221126-1+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-47268","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-47268","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-47268","date":"2026-10-08","epss":0.01745,"percentile":0.77093}],"risk":0.08725,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-47268","description":"ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication."},"relatedVulnerabilities":[{"id":"CVE-2025-47268","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47268","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-47268","date":"2026-10-08","epss":0.01745,"percentile":0.77093}],"urls":["https://bugzilla.suse.com/show_bug.cgi?id=1242300","https://github.com/Zephkek/ping-rtt-overflow/","https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40","https://github.com/iputils/iputils/issues/584","https://github.com/iputils/iputils/pull/585","https://github.com/iputils/iputils/releases/tag/20250602"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47268","description":"ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication."}]},{"artifact":{"id":"6896984bd13fb500","cpes":["cpe:2.3:a:libperl5.36:libperl5.36:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"libperl5.36","purl":"pkg:deb/debian/libperl5.36@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.36/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/libperl5.36/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/libperl5.36:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31486","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-08","epss":0.01742,"percentile":0.7706}],"risk":0.08710000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31486","description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates."},"relatedVulnerabilities":[{"id":"CVE-2023-31486","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-08","epss":0.01742,"percentile":0.7706}],"urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates."}]},{"artifact":{"id":"15c7b99e3a360b71","cpes":["cpe:2.3:a:perl:perl:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:597ab065de6968a59df65a9ba4f9c0872765e8b1e85cde5273d71bc953ab844f","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postinst"},{"path":"/var/lib/dpkg/info/perl.postrm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.postrm"},{"path":"/var/lib/dpkg/info/perl.preinst","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.preinst"},{"path":"/var/lib/dpkg/info/perl.prerm","layerID":"sha256:aa1dbfc2791ecd074b7d8d62559b2d90064d9d260b42107b15693ae3f9098b96","accessPath":"/var/lib/dpkg/info/perl.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31486","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-08","epss":0.01742,"percentile":0.7706}],"risk":0.08710000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31486","description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates."},"relatedVulnerabilities":[{"id":"CVE-2023-31486","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-08","epss":0.01742,"percentile":0.7706}],"urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:11:18.627Z","grype_db_version":"2026-10-09T06:32:32.000Z"}